Pierre Villard created NIFI-3121:
------------------------------------

             Summary: Remove read permissions on proxy resource for Node 
Identities
                 Key: NIFI-3121
                 URL: https://issues.apache.org/jira/browse/NIFI-3121
             Project: Apache NiFi
          Issue Type: Improvement
          Components: Core UI
    Affects Versions: 1.1.0, 1.0.0
            Reporter: Pierre Villard
            Priority: Trivial


When running a cluster, node identifies defined in {{authorizers.xml}} are 
granted read and write permissions in {{authorizations.xml}} although only 
write is required (and only write can be granted from UI for new users).

{noformat}
        <policy identifier="b806c392-b1aa-3254-a5df-add6ec5b9557" 
resource="/proxy" action="R">
            <user identifier="6f63f343-5d10-3153-b99a-2ec42f23b0c6"/>
            <user identifier="5bb41c7c-d546-3c94-8f35-574a8a39b1c2"/>
            <user identifier="02f804e5-9a18-3500-a907-ccc129ba21dd"/>
        </policy>
        <policy identifier="a8e45d9b-1c28-3efc-bcea-9f494348e1b9" 
resource="/proxy" action="W">
            <user identifier="6f63f343-5d10-3153-b99a-2ec42f23b0c6"/>
            <user identifier="02f804e5-9a18-3500-a907-ccc129ba21dd"/>
            <user identifier="5bb41c7c-d546-3c94-8f35-574a8a39b1c2"/>
            <user identifier="b1aa3cf1-0158-1000-0000-000036e9ad9b"/>
        </policy>
{noformat}

Removing read access would be nice to avoid confusion when looking at the UI to 
grant same policies to a new user.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to