Uploaded image for project: 'PicketBox '
  1. PicketBox
  2. SECURITY-13

Authorization Framework should work off of the roles in the Security Context

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Major Major
    • 2.0.GA
    • 2.0.GA
    • JBossSX
    • None

      There has been a discussion going on with reference to a Security Context in JBossSX. Refer to the forum thread

      As it stands, the Security Context is populated with the roles for the authenticated user, but the access checks that are happening (mainly for the jacc layer) needs to move away from the reliance on the role-group placed as a principal in the authenticated subject, but to use the roles in the Security Context.

            anil.saldhana Anil Saldanha (Inactive)
            anil.saldhana Anil Saldanha (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: