ChrisSamo632 commented on PR #6662:
URL: https://github.com/apache/nifi/pull/6662#issuecomment-1315859691

   > Thanks for the contribution @ChrisSamo632.
   > 
   > Reviewing the changes, are these new Authorization Schemes necessary? 
`NONE` is implied in the absence of credentials, and `PKI` appears to be 
handled already through the configuration of an SSL Context Service. It seems 
better to avoid introducing additional settings if they do not impact runtime 
behavior.
   
   I guess the question is whether people will understand that they can select 
(for example) BASIC auth but then leave username & password empty in order to 
get NOONE. Similarly, doing the same but configuring an SSLContextService (with 
keystore) for PKI auth
   
   The added validation simply adds some more guidance to what's already 
possible, I get that, but is it obvious enough that alternatives are available 
if we only have a mandatory Authorisation Scheme that only allows BASIC or 
API_KEY?


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to