[ 
https://issues.apache.org/jira/browse/NIFI-2595?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15427152#comment-15427152
 ] 

ASF GitHub Bot commented on NIFI-2595:
--------------------------------------

Github user asfgit closed the pull request at:

    https://github.com/apache/nifi/pull/892


> Address Reporting Tasks that create Controller level bulletins
> --------------------------------------------------------------
>
>                 Key: NIFI-2595
>                 URL: https://issues.apache.org/jira/browse/NIFI-2595
>             Project: Apache NiFi
>          Issue Type: Bug
>          Components: Extensions
>            Reporter: Matt Gilman
>            Assignee: Matt Gilman
>            Priority: Critical
>             Fix For: 1.0.0
>
>
> Some Reporting Tasks create bulletins directly through the 
> BulletinRepository. These are scoped to the Controller. Because they are 
> scoped to the Controller, they Bulletins are authorized at the Controller 
> level. If a user does not have access to the Reporting Task but does have 
> access to the Controller, these bulletins will be visible.
> Instead, Reporting Tasks should use the provided ComponentLog to create 
> component level bulletins which will be authorized according to the Reporting 
> Tasks policies.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to