Github user pvillard31 commented on the issue:
https://github.com/apache/nifi/pull/1923
Hey @mcgilman, I played a bit with it and that's really great. It's going
to be super useful. It also gave me the occasion to have a look at the Managed
Authorizer stuff - it's neat!
Tested using Apache Directory Studio and tried multiple scenarios: users
first, groups first, both users and groups. All is working as expected. I've
just one remark: when using users only search, but also setting the group name
attribute, the full DN of the group is used. Would be nice to also take into
account the group name attribute in that case (Note: the other way is working -
if searching for groups and defining the user name attribute, we don't have the
full DN for users).
Overall LGTM.
---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so, or if the feature is enabled but not working, please
contact infrastructure at [email protected] or file a JIRA ticket
with INFRA.
---