This is an automated email from the ASF dual-hosted git repository.

gosonzhang pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/inlong-website.git


The following commit(s) were added to refs/heads/master by this push:
     new 966096c8e6d [INLONG-1205][Doc] Added a security notice statement for 
the inlong-tubemq module (#1206)
966096c8e6d is described below

commit 966096c8e6da7811cf37999dc83f779fc71e519d
Author: Goson Zhang <[email protected]>
AuthorDate: Wed Sep 16 10:41:06 2026 +0800

    [INLONG-1205][Doc] Added a security notice statement for the inlong-tubemq 
module (#1206)
    
    Co-authored-by: gosonzhang <[email protected]>
---
 docs/security.md                                              | 2 ++
 i18n/zh-CN/docusaurus-plugin-content-docs/current/security.md | 2 ++
 2 files changed, 4 insertions(+)

diff --git a/docs/security.md b/docs/security.md
index 36bc65b3286..4cf883e3123 100644
--- a/docs/security.md
+++ b/docs/security.md
@@ -22,4 +22,6 @@ Apache InLong modules have clearly defined responsibilities 
for security boundar
 
 - The Manager module provides tenant isolation capabilities. Within the same 
tenant, any member can view all business information under that tenant, 
including Groups, Sinks, Streams, and more. Under the tenant permission model, 
only the Group owner has the authority to modify or delete their respective 
Groups, Sinks, Streams, and related data; normal operations performed by 
members within their granted permissions also fall under this category. To 
prevent business information from being  [...]
 
+- The inlong-tubemq module provides MQ-related message reception, storage, and 
management functions. By default, this module is deployed on a trusted network, 
so its implementation does not enforce authentication and authorization, but 
only provides an authentication framework for users to add their own 
authentication and authorization mechanisms as needed.
+
 It should be noted that the above explanation aims to clarify the security 
boundaries. We always welcome community input on enhancing codebase security 
and improving boundary protection, working together to drive the project's 
continuous evolution.
\ No newline at end of file
diff --git a/i18n/zh-CN/docusaurus-plugin-content-docs/current/security.md 
b/i18n/zh-CN/docusaurus-plugin-content-docs/current/security.md
index a0545b79bae..26647f1703a 100644
--- a/i18n/zh-CN/docusaurus-plugin-content-docs/current/security.md
+++ b/i18n/zh-CN/docusaurus-plugin-content-docs/current/security.md
@@ -22,4 +22,6 @@ Apache InLong 各模块基于其设计定位,对安全边界有明确的责任
 
 - Manager 模块提供租户隔离能力。在同一租户内,任意成员均可查看该租户下的全部业务信息,包括 Group、Sink、Stream 
等。在租户权限模型下,仅 Group 责任人有权对其名下的 Group、Sink、Stream 
等信息进行修改与删除;成员在被授予的权限范围内执行的正常操作亦属此列。如需防止业务信息被他人查看,用户只需确保未将无关人员加入当前租户。
 
+- inlong-tubemq 模块提供与 MQ 
相关的消息接收、存储和管理功能。默认情况下,该模块部署在受信任的网络上,因此其实现不强制执行身份验证和授权,而仅提供一个身份验证框架,供用户根据需要添加自己的身份验证和授权机制。
+
 需要说明的是,以上说明旨在明确安全边界。我们始终欢迎社区就强化代码库安全性、完善边界防护等提出建议,共同推动项目持续演进。
\ No newline at end of file

Reply via email to