goutamadwant opened a new issue, #12401: URL: https://github.com/apache/seatunnel/issues/12401
### Search before asking - [x] Searched existing issues and pull requests for Redis named-user authentication, username and ACL handling. No matching Connector-V2 fix was found; the older Spark Redis authentication PR concerns a different connector. ### What happened The shared Redis Connector-V2 source/sink connection helper does not authenticate as the configured `user`: - `SINGLE` calls password-only `AUTH`, followed by `ACL SETUSER user`. The latter administers an ACL entry; it does not change the connection's authenticated identity. - `CLUSTER` omits the username from its client configuration. Valid named-user credentials can therefore fail, or the connection can remain authenticated as `default` when the named and default users share a password. Connection setup can also modify ACL configuration when the default connection has administrative permission. Both source readers and sink writers use this helper. [Affected baseline helper](https://github.com/apache/seatunnel/blob/71860b4469bbd83722c81aa85ddd7e57f5f440de/seatunnel-connectors-v2/connector-redis/src/main/java/org/apache/seatunnel/connectors/seatunnel/redis/config/RedisParameters.java). ### SeaTunnel Version `dev` / `3.0.0-SNAPSHOT`, commit `71860b4469bbd83722c81aa85ddd7e57f5f440de`. No claim is made here that every released version was tested. ### SeaTunnel Config Relevant connection options for a disposable local Redis fixture; credentials below are synthetic test values: ```hocon mode = SINGLE host = "localhost" port = 6379 user = "seatunnel_named" auth = "named-password" db_num = 0 ``` For the cluster regression, use `mode = CLUSTER` and `redis_nodes = ["localhost:6379"]` against a cluster-enabled test server. Testcontainers supplies the actual mapped ports in the regression tests. ### Reproduction and running command The defect was reproduced against the real configuration parser and connection helper before changing production code: 1. Configure a disposable Redis server with a named ACL user allowed to run the connector's initialization commands (`INFO`, and `SELECT` for SINGLE mode). 2. Confirm that explicit named-user authentication succeeds and identifies the requested user. 3. Give the default and named users the same test password. Invoke `buildJedis()` with the options above. On the baseline, `ACL WHOAMI` reports `default`, not `seatunnel_named`. 4. In a separate cluster-enabled fixture owning all 16,384 slots, enable passwordless default access and configure a password-protected named user. The baseline helper sends password-only AUTH and fails despite valid named credentials. The regression tests are [Redis7Test.namedUserAuthentication and namedClusterAuthentication](https://github.com/goutamadwant/seatunnel/blob/3d4f8dc84fb130e53fbfc20bc731c5ec28e3bf23/seatunnel-connectors-v2/connector-redis/src/test/java/org/apache/seatunnel/connectors/seatunnel/redis/Redis7Test.java). Applying these regression tests to the unmodified baseline helper produced the failures below; running them with the proposed fix passes. ```shell ./mvnw -pl seatunnel-connectors-v2/connector-redis -am \ '-Dtest=Redis7Test#namedUserAuthentication+namedClusterAuthentication' \ -Dsurefire.failIfNoSpecifiedTests=false verify ``` This is a connection-helper reproduction, not a claim that a baseline full SeaTunnel job was run. The corrected source/sink path was subsequently validated using the existing engine E2E tests. ### Error Exception ```text SINGLE: expected: <seatunnel_named> but was: <default> CLUSTER: ERR AUTH <password> called without any password configured for the default user. ``` ### Expected behavior and proposed fix - Authenticate as the configured nonblank username in both SINGLE and CLUSTER modes. - Do not create or modify ACL users during connection setup. - Preserve no-auth/password-only behavior when the username is absent or blank. - Close connections if AUTH, SELECT or subsequent INFO/version initialization fails. Before: named-user configurations can fail or use the wrong identity, and SINGLE-mode connection setup can administer ACLs. After: existing named-user configurations use the intended identity without ACL administration. This allows source and sink jobs to use separately provisioned, restricted users and avoids leaking connections after failed initialization. ### Java or Scala Version Java 8 (Corretto 8u504) and Java 11 (Temurin 11.0.32.1). Initial standalone reproduction used Redis 7.2.16; the final job E2E fixture reported Redis 7.4.11. Redis 5 legacy behavior was also covered. ### Validation of the proposed fix - 67 Redis tests pass on each Java 8 and Java 11, with zero failures/errors/skips. - Covers named/default identity, same and distinct passwords, restricted keys and commands, selected database, absent/empty/whitespace credentials, unchanged ACL inventory and connection cleanup after failures. - A real single-node cluster owns all slots; multi-node redirection/failover and TLS have not been tested. - A fresh 70-module E2E reactor passes with Java 11 as the host JDK. The named-user source-to-sink job passes on Flink 1.13.6/1.15.3/1.18.0/1.20.1, Spark 2.4.6/3.3.0 and Zeta, verifying output and unchanged ACL inventory. Engine containers use their bundled JVMs. - Whole-repository `./mvnw -q -DskipTests verify` passes, including distribution packaging. This compiles the wider tests but does not execute them. ### Compatibility and migration No option rename, dependency addition or default-value change. The configured username will now be honored: jobs that accidentally relied on default-user authentication despite setting another username must supply valid credentials and permissions for the intended user, or remove `user` to retain default-user authentication. Named users require Redis 6 or later. With a nonblank username, passwords are passed unchanged; absent or empty passwords are sent as an empty string and require an ACL user that accepts them. EN/ZH connector documentation and incompatible-change notes describe this correction. ### Implementation [Prepared fix for review](https://github.com/apache/seatunnel/compare/dev...goutamadwant:fix/redis-named-auth). No PR has been opened from this branch yet. ### Are you willing to submit PR? - [x] Yes, the implementation and regression coverage are prepared. ### Code of Conduct - [x] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct). -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
