How to use Mosquittos Dynamic Security Plugin?

Hi,

i am a little confused right now and hope someone here can help / clarify.

the environment is

  • HAOS (vm)
  • MQTT Broker (mosquitto lxc)
  • shelly plug s (with tasmota)

now i have to goals which i want to achieve:

  1. HAOS should not be able to switch (on/off) the shelly plug
  2. the shelly plug should only be able to push their data and the respected user should not be able to control anything

The Documentation i found was this:

every device already has its own mqtt user.
My problem is creating the necessary ACLs (i think)

with kind regards