[mod_hiredis] Add username support for Redis ACL authentication - #3146
Open
dmalgarise wants to merge 1 commit into
Open
[mod_hiredis] Add username support for Redis ACL authentication#3146dmalgarise wants to merge 1 commit into
dmalgarise wants to merge 1 commit into
Conversation
dmalgarise
marked this pull request as ready for review
September 8, 2026 07:13
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This pull request adds optional Redis ACL username support to
mod_hiredis.Redis 6 introduced ACL authentication using:
AUTH username passwordmod_hirediscurrently supports only the password, which implicitly authenticates the Redis default user. This prevents FreeSWITCH deployments from using a dedicated least-privilege Redis ACL user.The new optional username connection parameter changes the authentication behavior as follows:
AUTH username password.AUTH passwordbehavior.AUTH.The change is backward compatible with existing configurations.
Type of Change
Related Issues
Closes #3145
Testing
Manual integration testing was performed in an isolated Docker environment using:
The patched mod_hiredis module was compiled from commit 9230f7e and loaded successfully by FreeSWITCH.
The following scenarios were verified:
NOAUTH Authenticationrequired.hiredis_rawacl PING returned PONG.hiredis_rawlegacy PING returned PONG.hiredis_rawacl PING returned PONG, confirming successful reconnection and ACL re-authentication.(Live SignalWire credentials are not applicable to this change).
Checklist
Additional Notes
The optional username is stored per Redis connection and is applied during both initial authentication and reconnection of pooled connections.
The shipped
hiredis.conf.xmlexample documents the new parameter without enabling it by default, preserving compatibility with Redis versions earlier than 6.