<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Masking of Authentication token in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Masking-of-Authentication-token/m-p/321615#M228477</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should not be possible.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If put the token into a variable, then everyone else can see the variable.&lt;/LI&gt;&lt;LI&gt;If you put it into a parameter, you also cannot use the secure parameter because you can put these only in sensitive fields.&lt;/LI&gt;&lt;LI&gt;When you use normal parameter, you have the same behavior as with the variables.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I'm excited to see if anyone else comes up with a solution!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jul 2021 08:04:39 GMT</pubDate>
    <dc:creator>janis-ax</dc:creator>
    <dc:date>2021-07-27T08:04:39Z</dc:date>
    <item>
      <title>Masking of Authentication token</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Masking-of-Authentication-token/m-p/321582#M228462</link>
      <description>&lt;P&gt;Is it possible to mask or greyed out the Token passed in Custom Property (Authentication )?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have one Token received from one API and have to pass it to another request.&lt;/P&gt;&lt;P&gt;Issue: If I &lt;STRONG&gt;pass&lt;/STRONG&gt; the token in custom property, it will be visible to all users who can access the flowfile. I need to mask these token as these value are displayed in Attribute and Content.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for early response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 15:42:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Masking-of-Authentication-token/m-p/321582#M228462</guid>
      <dc:creator>midee</dc:creator>
      <dc:date>2021-07-26T15:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Masking of Authentication token</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Masking-of-Authentication-token/m-p/321615#M228477</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should not be possible.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If put the token into a variable, then everyone else can see the variable.&lt;/LI&gt;&lt;LI&gt;If you put it into a parameter, you also cannot use the secure parameter because you can put these only in sensitive fields.&lt;/LI&gt;&lt;LI&gt;When you use normal parameter, you have the same behavior as with the variables.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I'm excited to see if anyone else comes up with a solution!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 08:04:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Masking-of-Authentication-token/m-p/321615#M228477</guid>
      <dc:creator>janis-ax</dc:creator>
      <dc:date>2021-07-27T08:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Masking of Authentication token</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Masking-of-Authentication-token/m-p/321692#M228524</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/87710"&gt;@midee&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/90327"&gt;@janis-ax&lt;/a&gt;&amp;nbsp;is correct that this is not possible.&lt;BR /&gt;&lt;BR /&gt;"ONLY" sensitive attributes can be encrypted/masked.&amp;nbsp; Only component properties coded to as a sensitive property field would be able to decrypt an encrypted/masked value.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;If setting policies to block specific users from being able to view the data on these components, you may want to look at other options for performing these endpoint authentication/authorization actions.&amp;nbsp; For example, with the NiFi endpoints you could use mutual TLS via certificates instead of token based authentication for accessing the endpoints.&amp;nbsp; This does not mean you need to stop using or un-configure the token based authentication methods for access to your secured NiFi.&lt;BR /&gt;&lt;BR /&gt;If the endpoint you are trying to reach is not NiFi, you may want to see what other options it may offer for authentication that are not token based.&lt;BR /&gt;&lt;BR /&gt;Hope this helped,&lt;BR /&gt;Matt&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 17:53:27 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Masking-of-Authentication-token/m-p/321692#M228524</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2021-07-28T17:53:27Z</dc:date>
    </item>
  </channel>
</rss>

