goutamadwant opened a new issue, #12401:
URL: https://github.com/apache/seatunnel/issues/12401

   ### Search before asking
   
   - [x] Searched existing issues and pull requests for Redis named-user 
authentication, username and ACL handling. No matching Connector-V2 fix was 
found; the older Spark Redis authentication PR concerns a different connector.
   
   ### What happened
   
   The shared Redis Connector-V2 source/sink connection helper does not 
authenticate as the configured `user`:
   
   - `SINGLE` calls password-only `AUTH`, followed by `ACL SETUSER user`. The 
latter administers an ACL entry; it does not change the connection's 
authenticated identity.
   - `CLUSTER` omits the username from its client configuration.
   
   Valid named-user credentials can therefore fail, or the connection can 
remain authenticated as `default` when the named and default users share a 
password. Connection setup can also modify ACL configuration when the default 
connection has administrative permission. Both source readers and sink writers 
use this helper.
   
   [Affected baseline 
helper](https://github.com/apache/seatunnel/blob/71860b4469bbd83722c81aa85ddd7e57f5f440de/seatunnel-connectors-v2/connector-redis/src/main/java/org/apache/seatunnel/connectors/seatunnel/redis/config/RedisParameters.java).
   
   ### SeaTunnel Version
   
   `dev` / `3.0.0-SNAPSHOT`, commit `71860b4469bbd83722c81aa85ddd7e57f5f440de`. 
No claim is made here that every released version was tested.
   
   ### SeaTunnel Config
   
   Relevant connection options for a disposable local Redis fixture; 
credentials below are synthetic test values:
   
   ```hocon
   mode = SINGLE
   host = "localhost"
   port = 6379
   user = "seatunnel_named"
   auth = "named-password"
   db_num = 0
   ```
   
   For the cluster regression, use `mode = CLUSTER` and `redis_nodes = 
["localhost:6379"]` against a cluster-enabled test server. Testcontainers 
supplies the actual mapped ports in the regression tests.
   
   ### Reproduction and running command
   
   The defect was reproduced against the real configuration parser and 
connection helper before changing production code:
   
   1. Configure a disposable Redis server with a named ACL user allowed to run 
the connector's initialization commands (`INFO`, and `SELECT` for SINGLE mode).
   2. Confirm that explicit named-user authentication succeeds and identifies 
the requested user.
   3. Give the default and named users the same test password. Invoke 
`buildJedis()` with the options above. On the baseline, `ACL WHOAMI` reports 
`default`, not `seatunnel_named`.
   4. In a separate cluster-enabled fixture owning all 16,384 slots, enable 
passwordless default access and configure a password-protected named user. The 
baseline helper sends password-only AUTH and fails despite valid named 
credentials.
   
   The regression tests are [Redis7Test.namedUserAuthentication and 
namedClusterAuthentication](https://github.com/goutamadwant/seatunnel/blob/3d4f8dc84fb130e53fbfc20bc731c5ec28e3bf23/seatunnel-connectors-v2/connector-redis/src/test/java/org/apache/seatunnel/connectors/seatunnel/redis/Redis7Test.java).
 Applying these regression tests to the unmodified baseline helper produced the 
failures below; running them with the proposed fix passes.
   
   ```shell
   ./mvnw -pl seatunnel-connectors-v2/connector-redis -am \
     '-Dtest=Redis7Test#namedUserAuthentication+namedClusterAuthentication' \
     -Dsurefire.failIfNoSpecifiedTests=false verify
   ```
   
   This is a connection-helper reproduction, not a claim that a baseline full 
SeaTunnel job was run. The corrected source/sink path was subsequently 
validated using the existing engine E2E tests.
   
   ### Error Exception
   
   ```text
   SINGLE: expected: <seatunnel_named> but was: <default>
   CLUSTER: ERR AUTH <password> called without any password configured for the 
default user.
   ```
   
   ### Expected behavior and proposed fix
   
   - Authenticate as the configured nonblank username in both SINGLE and 
CLUSTER modes.
   - Do not create or modify ACL users during connection setup.
   - Preserve no-auth/password-only behavior when the username is absent or 
blank.
   - Close connections if AUTH, SELECT or subsequent INFO/version 
initialization fails.
   
   Before: named-user configurations can fail or use the wrong identity, and 
SINGLE-mode connection setup can administer ACLs.
   
   After: existing named-user configurations use the intended identity without 
ACL administration. This allows source and sink jobs to use separately 
provisioned, restricted users and avoids leaking connections after failed 
initialization.
   
   ### Java or Scala Version
   
   Java 8 (Corretto 8u504) and Java 11 (Temurin 11.0.32.1). Initial standalone 
reproduction used Redis 7.2.16; the final job E2E fixture reported Redis 
7.4.11. Redis 5 legacy behavior was also covered.
   
   ### Validation of the proposed fix
   
   - 67 Redis tests pass on each Java 8 and Java 11, with zero 
failures/errors/skips.
   - Covers named/default identity, same and distinct passwords, restricted 
keys and commands, selected database, absent/empty/whitespace credentials, 
unchanged ACL inventory and connection cleanup after failures.
   - A real single-node cluster owns all slots; multi-node redirection/failover 
and TLS have not been tested.
   - A fresh 70-module E2E reactor passes with Java 11 as the host JDK. The 
named-user source-to-sink job passes on Flink 1.13.6/1.15.3/1.18.0/1.20.1, 
Spark 2.4.6/3.3.0 and Zeta, verifying output and unchanged ACL inventory. 
Engine containers use their bundled JVMs.
   - Whole-repository `./mvnw -q -DskipTests verify` passes, including 
distribution packaging. This compiles the wider tests but does not execute them.
   
   ### Compatibility and migration
   
   No option rename, dependency addition or default-value change. The 
configured username will now be honored: jobs that accidentally relied on 
default-user authentication despite setting another username must supply valid 
credentials and permissions for the intended user, or remove `user` to retain 
default-user authentication.
   
   Named users require Redis 6 or later. With a nonblank username, passwords 
are passed unchanged; absent or empty passwords are sent as an empty string and 
require an ACL user that accepts them. EN/ZH connector documentation and 
incompatible-change notes describe this correction.
   
   ### Implementation
   
   [Prepared fix for 
review](https://github.com/apache/seatunnel/compare/dev...goutamadwant:fix/redis-named-auth).
 No PR has been opened from this branch yet.
   
   ### Are you willing to submit PR?
   
   - [x] Yes, the implementation and regression coverage are prepared.
   
   ### Code of Conduct
   
   - [x] I agree to follow this project's [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to