sijie commented on issue #6122: [pulsar-admin] allow tenant admin to manage 
subscription permission
URL: https://github.com/apache/pulsar/pull/6122#issuecomment-580982331
 
 
   It is 2.6.0 now. It has been 2 major releases since 2.3. If an API is 
exposed publicly, changing the behavior should be treated as a “breaking” 
change. Users should have been notified of this behavior change.
   
   This change is not just about adding flexibility. From security point of 
view, this endpoint was only allowed for super-user but this change relaxes the 
permissions to a tenant admin. This is a red flag to a lot of enterprises. 
Because you are allowing a different set of people accessing the API. Correct 
me if I misunderstood this change here.

----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
[email protected]


With regards,
Apache Git Services

Reply via email to