I notice that the HA MQTT Broker add-on allows any HA user to post/read all messages.
When Mosquitto is installed via a container (or service), ACL can be fine tuned very precisely.
Is there any way to achieve ACL control via the HA add-on as can be done with a container/service? Some may consider the lack of ability to fine tune ACL rules to be a vulnerability.