The limitations in User Authentication within the event broker

Do anyone have thoughts on this? It’s an essential step to prevent authorization issues.