Carsten, I'm going to rush this next sentence out because I know that you're done for the day and then I won't have ideas to work on while you're away :-), then I'll reply to your previous note.
I think that the restriction you describe (one role per user) means that the SunRise authentication is potentially mis-using the word 'role'. You're using it to denote a profile name, nothing more. It'll never really replace (or integrate with) roles in the Servlet or permissions sense if it's restricted to one role at a time. Now on to reply... Per --------------------------------------------------------------------- Please check that your question has not already been answered in the FAQ before posting. <http://xml.apache.org/cocoon/faq/index.html> To unsubscribe, e-mail: <[EMAIL PROTECTED]> For additional commands, e-mail: <[EMAIL PROTECTED]>