Author: buildbot
Date: Sat Aug  1 21:44:56 2015
New Revision: 960457

Log:
Staging update by buildbot for deltaspike

Modified:
    websites/staging/deltaspike/trunk/content/   (props changed)
    websites/staging/deltaspike/trunk/content/contributors.html
    websites/staging/deltaspike/trunk/content/draft/backlog.html
    websites/staging/deltaspike/trunk/content/draft/cdi-1.1-proposals.html
    websites/staging/deltaspike/trunk/content/draft/drafts.html
    websites/staging/deltaspike/trunk/content/draft/exception_draft.html
    websites/staging/deltaspike/trunk/content/draft/index2.html
    websites/staging/deltaspike/trunk/content/draft/se-features-ranking.html
    websites/staging/deltaspike/trunk/content/index.html
    websites/staging/deltaspike/trunk/content/retired/I18n.html
    websites/staging/deltaspike/trunk/content/retired/_features.html
    websites/staging/deltaspike/trunk/content/retired/_modules.html
    websites/staging/deltaspike/trunk/content/retired/bean-validation.html
    websites/staging/deltaspike/trunk/content/retired/build.html
    websites/staging/deltaspike/trunk/content/retired/community.html
    websites/staging/deltaspike/trunk/content/retired/configuration.html
    websites/staging/deltaspike/trunk/content/retired/container-control.html
    websites/staging/deltaspike/trunk/content/retired/core.html
    websites/staging/deltaspike/trunk/content/retired/data.html
    websites/staging/deltaspike/trunk/content/retired/documentation.html
    websites/staging/deltaspike/trunk/content/retired/download.html
    websites/staging/deltaspike/trunk/content/retired/examples.html
    websites/staging/deltaspike/trunk/content/retired/exceptions.html
    websites/staging/deltaspike/trunk/content/retired/javadoc.html
    websites/staging/deltaspike/trunk/content/retired/jpa.html
    websites/staging/deltaspike/trunk/content/retired/jsf.html
    websites/staging/deltaspike/trunk/content/retired/migration-guide.html
    websites/staging/deltaspike/trunk/content/retired/new-committer.html
    websites/staging/deltaspike/trunk/content/retired/news.html
    websites/staging/deltaspike/trunk/content/retired/partial-bean.html
    websites/staging/deltaspike/trunk/content/retired/project-name.html
    websites/staging/deltaspike/trunk/content/retired/projectstage.html
    websites/staging/deltaspike/trunk/content/retired/release-preparation.html
    websites/staging/deltaspike/trunk/content/retired/scheduler.html
    websites/staging/deltaspike/trunk/content/retired/security.html
    websites/staging/deltaspike/trunk/content/retired/servlet.html
    websites/staging/deltaspike/trunk/content/retired/source.html
    websites/staging/deltaspike/trunk/content/retired/spi.html
    websites/staging/deltaspike/trunk/content/retired/steps_for_a_release.html
    
websites/staging/deltaspike/trunk/content/retired/suggested-git-workflows.html
    websites/staging/deltaspike/trunk/content/retired/support.html
    websites/staging/deltaspike/trunk/content/retired/supporters.html
    websites/staging/deltaspike/trunk/content/retired/test-control.html

Propchange: websites/staging/deltaspike/trunk/content/
------------------------------------------------------------------------------
--- cms:source-revision (original)
+++ cms:source-revision Sat Aug  1 21:44:56 2015
@@ -1 +1 @@
-1693770
+1693771

Modified: websites/staging/deltaspike/trunk/content/contributors.html
==============================================================================
--- websites/staging/deltaspike/trunk/content/contributors.html (original)
+++ websites/staging/deltaspike/trunk/content/contributors.html Sat Aug  1 
21:44:56 2015
@@ -87,7 +87,7 @@
     <li>
         <div class="photo">
             <a href="">
-                <img 
src="http://gravatar.com/avatar/7bc530b3b080b9fd6a018db84bda9884?s=140"/>
+                <img src="http://gravatar.com/avatar/?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
@@ -95,14 +95,14 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>cody.lerum</h3>
+        <h3>kenfinnigan</h3>
         
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img 
src="http://gravatar.com/avatar/fc0369fe2a90a65801ef65ac407f5c09?s=140"/>
+            <a href="http://gravatar.com/jimjagski";>
+                <img 
src="http://gravatar.com/avatar/a86203bd1e538f2a4e58eb8850fb66ef?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
@@ -110,37 +110,37 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>arne.limburg</h3>
+        <h3>jimjag</h3>
         
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img src="http://gravatar.com/avatar/?s=140"/>
+            <a href="http://gravatar.com/codylerum";>
+                <img 
src="http://gravatar.com/avatar/1137f0cfb63b80013b4fa20069d99e8f?s=140"/>
             </a>
             <ul>
-                <li><a href="#">Blog</a></li>
-                <li><a href="#">Twitter</a></li>
-                <li><a href="#">GitHub</a></li>
+                <li><a href="http://www.outjected.com";>Blog</a></li>
+                <li><a href="http://twitter.com/codylerum";>Twitter</a></li>
+                <li><a href="http://github.com/codylerum";>GitHub</a></li>
             </ul>
         </div>
-        <h3>jakobk</h3>
-        
+        <h3>Cody Lerum</h3>
+        Networking Guy and Coder
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img 
src="http://gravatar.com/avatar/6f3b4f34837a2289844caf64e9680bb8?s=140"/>
+            <a href="http://gravatar.com/johnament";>
+                <img 
src="http://gravatar.com/avatar/b2c001ddd859374ff0b328b9a22975f4?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
-                <li><a href="#">Twitter</a></li>
+                <li><a href="http://twitter.com/JohnAment";>Twitter</a></li>
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>david.blevins</h3>
+        <h3>John D. Ament</h3>
         
     </li>
 
@@ -170,14 +170,14 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>antoinesd</h3>
+        <h3>jharting</h3>
         
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img 
src="http://gravatar.com/avatar/fa74dd8256e4d02c6bb9a35c193f53bf?s=140"/>
+            <a href="http://gravatar.com/cmoulliard";>
+                <img 
src="http://gravatar.com/avatar/76f8638c31c1128a30fe31f1564ab704?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
@@ -185,14 +185,14 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>lightguardjp</h3>
+        <h3>Charles Moulliard</h3>
         
     </li>
 
     <li>
         <div class="photo">
             <a href="">
-                <img src="http://gravatar.com/avatar/?s=140"/>
+                <img 
src="http://gravatar.com/avatar/fa74dd8256e4d02c6bb9a35c193f53bf?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
@@ -200,14 +200,14 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>kenfinnigan</h3>
+        <h3>lightguardjp</h3>
         
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img 
src="http://gravatar.com/avatar/47b1d3b06f04424bb396ad5b621ca51e?s=140"/>
+            <a href="http://gravatar.com/matthiaswessendorf";>
+                <img 
src="http://gravatar.com/avatar/df135e9a2604ec2ce5d12ad049a8c99b?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
@@ -215,8 +215,8 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>johndament</h3>
-        
+        <h3>Matthias Wessendorf</h3>
+        Howdy!
     </li>
 
     <li>
@@ -230,23 +230,23 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>jharting</h3>
+        <h3>pmuir</h3>
         
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img src="http://gravatar.com/avatar/?s=140"/>
+            <a href="http://gravatar.com/rmannibucau";>
+                <img 
src="http://gravatar.com/avatar/3183d91957cfbe06163853d6da2a965e?s=140"/>
             </a>
             <ul>
-                <li><a href="#">Blog</a></li>
-                <li><a href="#">Twitter</a></li>
-                <li><a href="#">GitHub</a></li>
+                <li><a href="http://rmannibucau.wordpress.com/";>Blog</a></li>
+                <li><a href="http://twitter.com/rmannibucau";>Twitter</a></li>
+                <li><a href="http://github.com/rmannibucau";>GitHub</a></li>
             </ul>
         </div>
-        <h3>bleathem</h3>
-        
+        <h3>Romain Manni-Bucau</h3>
+        Apache TomEE, OpenEJB, OpenWebBeans, DeltaSpike, BatchEE and Sirona 
committer.
     </li>
 
     <li>
@@ -260,14 +260,14 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>chkal</h3>
+        <h3>lincolnthree</h3>
         
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img src="http://gravatar.com/avatar/?s=140"/>
+            <a href="http://gravatar.com/sbryzak";>
+                <img 
src="http://gravatar.com/avatar/8dd6e2d1651d8f9526332d0798856320?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
@@ -275,29 +275,29 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>cmoulliard</h3>
+        <h3>sbryzak</h3>
         
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img src="http://gravatar.com/avatar/?s=140"/>
+            <a href="http://gravatar.com/rafabene";>
+                <img 
src="http://gravatar.com/avatar/087b923821c70dc1f8965b036d6aa6e2?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
-                <li><a href="#">Twitter</a></li>
+                <li><a href="http://twitter.com/rafabene";>Twitter</a></li>
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>jimjag</h3>
+        <h3>Rafael Benevides</h3>
         
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img src="http://gravatar.com/avatar/?s=140"/>
+            <a href="http://gravatar.com/struberg";>
+                <img 
src="http://gravatar.com/avatar/30fae5bce90608fb3df5c018c586aea6?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
@@ -305,14 +305,14 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>gastaldi</h3>
-        
+        <h3>Mark Struberg</h3>
+        I&#39;m an Apache Software Foundation member blogging about Java, ??C, 
TheASF, OpenWebBeans, Maven, M...
     </li>
 
     <li>
         <div class="photo">
             <a href="">
-                <img src="http://gravatar.com/avatar/?s=140"/>
+                <img 
src="http://gravatar.com/avatar/fc0369fe2a90a65801ef65ac407f5c09?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
@@ -320,7 +320,7 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>lincolnthree</h3>
+        <h3>arne.limburg</h3>
         
     </li>
 
@@ -335,29 +335,29 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>lukaszlenart</h3>
+        <h3>jakobk</h3>
         
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img src="http://gravatar.com/avatar/?s=140"/>
+            <a href="http://gravatar.com/dblevins";>
+                <img 
src="http://gravatar.com/avatar/76f50702f0bc1c9f173caf630d349d27?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
-                <li><a href="#">Twitter</a></li>
-                <li><a href="#">GitHub</a></li>
+                <li><a href="http://twitter.com/dblevins";>Twitter</a></li>
+                <li><a href="http://github.com/dblevins";>GitHub</a></li>
             </ul>
         </div>
-        <h3>marius</h3>
-        
+        <h3>David Blevins</h3>
+        David Blevins is a founder of the Apache TomEE, OpenEJB and Geronimo 
projects. David was a member...
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img src="http://gravatar.com/avatar/?s=140"/>
+            <a href="http://gravatar.com/chkal";>
+                <img 
src="http://gravatar.com/avatar/218ec7f7a231a8a95afd6c038e5d4706?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
@@ -365,7 +365,7 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>matzew</h3>
+        <h3>Christian Kaltepoth</h3>
         
     </li>
 
@@ -380,7 +380,7 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>pmuir</h3>
+        <h3>mojavelinux</h3>
         
     </li>
 
@@ -395,7 +395,7 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>rmannibucau</h3>
+        <h3>gastaldi</h3>
         
     </li>
 
@@ -410,14 +410,14 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>sbryzak</h3>
+        <h3>antoinesd</h3>
         
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img src="http://gravatar.com/avatar/?s=140"/>
+            <a href="http://gravatar.com/bleathem";>
+                <img 
src="http://gravatar.com/avatar/81c9e01b747320136fa9b6e9e168e000?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
@@ -425,14 +425,14 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>mojavelinux</h3>
+        <h3>bleathem</h3>
         
     </li>
 
     <li>
         <div class="photo">
-            <a href="">
-                <img src="http://gravatar.com/avatar/?s=140"/>
+            <a href="http://gravatar.com/lukaszlenart";>
+                <img 
src="http://gravatar.com/avatar/66138c58f4326c325e6c2bddf668eab4?s=140"/>
             </a>
             <ul>
                 <li><a href="#">Blog</a></li>
@@ -440,7 +440,7 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>rafabene</h3>
+        <h3>lukaszlenart</h3>
         
     </li>
 
@@ -455,7 +455,7 @@
                 <li><a href="#">GitHub</a></li>
             </ul>
         </div>
-        <h3>struberg</h3>
+        <h3>marius</h3>
         
     </li>
 
@@ -470,7 +470,7 @@
       <hr>
 
       <footer>
-        <p>Copyright © 2011-2014 The Apache Software Foundation, Licensed 
under the Apache License, Version 2.0.</p>
+        <p>Copyright © 2011-2015 The Apache Software Foundation, Licensed 
under the Apache License, Version 2.0.</p>
         <p>Apache and the Apache feather logo are trademarks of The Apache 
Software Foundation.</p>
       </footer>
 

Modified: websites/staging/deltaspike/trunk/content/draft/backlog.html
==============================================================================
--- websites/staging/deltaspike/trunk/content/draft/backlog.html (original)
+++ websites/staging/deltaspike/trunk/content/draft/backlog.html Sat Aug  1 
21:44:56 2015
@@ -80,8 +80,19 @@
               <div class="page-title">
                 <h1>Backlog</h1>
               </div>
-              <h1 id="deltaspike-forge-plugin">DeltaSpike-Forge Plugin</h1>
-<h2 id="possible-setup-for-v01">Possible Setup for v0.1</h2>
+              <style type="text/css">
+/* The following code is added by mdx_elementid.py
+   It was originally lifted from http://subversion.apache.org/style/site.css */
+/*
+ * Hide class="elementid-permalink", except when an enclosing heading
+ * has the :hover property.
+ */
+.headerlink, .elementid-permalink {
+  visibility: hidden;
+}
+h2:hover > .headerlink, h3:hover > .headerlink, h1:hover > .headerlink, 
h6:hover > .headerlink, h4:hover > .headerlink, h5:hover > .headerlink, 
dt:hover > .elementid-permalink { visibility: visible }</style>
+<h1 id="deltaspike-forge-plugin">DeltaSpike-Forge Plugin<a class="headerlink" 
href="#deltaspike-forge-plugin" title="Permanent link">&para;</a></h1>
+<h2 id="possible-setup-for-v01">Possible Setup for v0.1<a class="headerlink" 
href="#possible-setup-for-v01" title="Permanent link">&para;</a></h2>
 <ul>
 <li>Project-Setup</li>
 <li>Deactivate DeltaSpike Features
@@ -101,14 +112,14 @@
 <li>Config
    ** List all DeltaSpikeConfig implementations</li>
 </ul>
-<h1 id="osgi-integration">OSGI integration</h1>
+<h1 id="osgi-integration">OSGI integration<a class="headerlink" 
href="#osgi-integration" title="Permanent link">&para;</a></h1>
 <p>Could be nice to be able to get OSGi services injected. A proposal is here: 
https://gist.github.com/1515423</p>
 <p>Bundle and BundleContext could be injectable too.</p>
 <p>A bundlelistener and a servicelistener could send CDI event to notify of 
OSGi states.</p>
-<h1 id="spring-cdi-integration">Spring CDI Integration</h1>
-<h2 id="seam-spring"><em>Seam Spring</em></h2>
-<h3 id="existing-features-as-of-seam-spring-31"><em>Existing features (as of 
Seam Spring 3.1)</em></h3>
-<table>
+<h1 id="spring-cdi-integration">Spring CDI Integration<a class="headerlink" 
href="#spring-cdi-integration" title="Permanent link">&para;</a></h1>
+<h2 id="seam-spring"><em>Seam Spring</em><a class="headerlink" 
href="#seam-spring" title="Permanent link">&para;</a></h2>
+<h3 id="existing-features-as-of-seam-spring-31"><em>Existing features (as of 
Seam Spring 3.1)</em><a class="headerlink" 
href="#existing-features-as-of-seam-spring-31" title="Permanent 
link">&para;</a></h3>
+<table class="table">
 <thead>
 <tr>
 <th></th>
@@ -170,7 +181,7 @@
 </tr>
 </tbody>
 </table>
-<h3 id="planned-features">Planned features</h3>
+<h3 id="planned-features">Planned features<a class="headerlink" 
href="#planned-features" title="Permanent link">&para;</a></h3>
 <p>From the [module site|http://seamframework.org/Seam3/SpringModule] , as 
well as new</p>
 <p>|| Feature &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 
&nbsp; &nbsp; || "Requires" changes || Ranking || Objections ||
 | CDI eventing/Spring eventing bridge | n/a | 8 | |
@@ -181,7 +192,7 @@
       <hr>
 
       <footer>
-        <p>Copyright © 2011-2014 The Apache Software Foundation, Licensed 
under the Apache License, Version 2.0.</p>
+        <p>Copyright © 2011-2015 The Apache Software Foundation, Licensed 
under the Apache License, Version 2.0.</p>
         <p>Apache and the Apache feather logo are trademarks of The Apache 
Software Foundation.</p>
       </footer>
 

Modified: websites/staging/deltaspike/trunk/content/draft/cdi-1.1-proposals.html
==============================================================================
--- websites/staging/deltaspike/trunk/content/draft/cdi-1.1-proposals.html 
(original)
+++ websites/staging/deltaspike/trunk/content/draft/cdi-1.1-proposals.html Sat 
Aug  1 21:44:56 2015
@@ -80,8 +80,19 @@
               <div class="page-title">
                 <h1>porposed CDI-1.1 enhancements</h1>
               </div>
-              <p>This page contains proposals of the DeltaSpike community for 
CDI 1.1. Some parts might be used also for DeltaSpike for CDI 1.0.</p>
-<h1 id="context-management-with-community-agreement">Context Management (with 
community agreement)</h1>
+              <style type="text/css">
+/* The following code is added by mdx_elementid.py
+   It was originally lifted from http://subversion.apache.org/style/site.css */
+/*
+ * Hide class="elementid-permalink", except when an enclosing heading
+ * has the :hover property.
+ */
+.headerlink, .elementid-permalink {
+  visibility: hidden;
+}
+h2:hover > .headerlink, h3:hover > .headerlink, h1:hover > .headerlink, 
h6:hover > .headerlink, h4:hover > .headerlink, h5:hover > .headerlink, 
dt:hover > .elementid-permalink { visibility: visible }</style>
+<p>This page contains proposals of the DeltaSpike community for CDI 1.1. Some 
parts might be used also for DeltaSpike for CDI 1.0.</p>
+<h1 id="context-management-with-community-agreement">Context Management (with 
community agreement)<a class="headerlink" 
href="#context-management-with-community-agreement" title="Permanent 
link">&para;</a></h1>
 <div class="codehilite"><pre><span class="n">public</span> <span 
class="n">interface</span> <span class="n">ManagedContext</span> <span 
class="n">extends</span> <span class="n">Context</span>
 <span class="p">{</span>
     <span class="n">void</span> <span class="n">start</span><span 
class="p">();</span>
@@ -92,7 +103,7 @@
 
 
 <p>[TODO]</p>
-<h2 id="context-management-of-weld-core-api">Context Management of Weld-Core 
(API)</h2>
+<h2 id="context-management-of-weld-core-api">Context Management of Weld-Core 
(API)<a class="headerlink" href="#context-management-of-weld-core-api" 
title="Permanent link">&para;</a></h2>
 <p>A set of dependent scoped built in beans are available for context 
management.</p>
 <div class="codehilite"><pre><span class="cm">/**</span>
 <span class="cm"> * &lt;p&gt;</span>
@@ -386,7 +397,7 @@
 </pre></div>
 
 
-<h1 id="map-bound-contexts">Map-bound contexts</h1>
+<h1 id="map-bound-contexts">Map-bound contexts<a class="headerlink" 
href="#map-bound-contexts" title="Permanent link">&para;</a></h1>
 <p>We may also wish to add map-bound contexts, in which the contexts are 
backed by a map. Note that the example javadoc above needs expanding if we 
do.</p>
 <p>Add these dependent scoped beans:</p>
 <div class="codehilite"><pre><span class="cm">/**</span>
@@ -521,7 +532,7 @@
 </pre></div>
 
 
-<h3 id="context-conversation-management-of-weld-core-api">Context / 
Conversation Management of Weld-Core (API)</h3>
+<h3 id="context-conversation-management-of-weld-core-api">Context / 
Conversation Management of Weld-Core (API)<a class="headerlink" 
href="#context-conversation-management-of-weld-core-api" title="Permanent 
link">&para;</a></h3>
 <div class="codehilite"><pre><span class="cm">/**</span>
 <span class="cm"> * &lt;p&gt;</span>
 <span class="cm"> * The built in conversation context is associated with</span>
@@ -803,7 +814,7 @@ public interface ManagedConversation ext
       <hr>
 
       <footer>
-        <p>Copyright © 2011-2014 The Apache Software Foundation, Licensed 
under the Apache License, Version 2.0.</p>
+        <p>Copyright © 2011-2015 The Apache Software Foundation, Licensed 
under the Apache License, Version 2.0.</p>
         <p>Apache and the Apache feather logo are trademarks of The Apache 
Software Foundation.</p>
       </footer>
 

Modified: websites/staging/deltaspike/trunk/content/draft/drafts.html
==============================================================================
--- websites/staging/deltaspike/trunk/content/draft/drafts.html (original)
+++ websites/staging/deltaspike/trunk/content/draft/drafts.html Sat Aug  1 
21:44:56 2015
@@ -80,8 +80,19 @@
               <div class="page-title">
                 <h1>Draft</h1>
               </div>
-              <h1 id="exception-control-draft">Exception Control Draft</h1>
-<h1 id="agreed-api">Agreed API</h1>
+              <style type="text/css">
+/* The following code is added by mdx_elementid.py
+   It was originally lifted from http://subversion.apache.org/style/site.css */
+/*
+ * Hide class="elementid-permalink", except when an enclosing heading
+ * has the :hover property.
+ */
+.headerlink, .elementid-permalink {
+  visibility: hidden;
+}
+h2:hover > .headerlink, h3:hover > .headerlink, h1:hover > .headerlink, 
h6:hover > .headerlink, h4:hover > .headerlink, h5:hover > .headerlink, 
dt:hover > .elementid-permalink { visibility: visible }</style>
+<h1 id="exception-control-draft">Exception Control Draft<a class="headerlink" 
href="#exception-control-draft" title="Permanent link">&para;</a></h1>
+<h1 id="agreed-api">Agreed API<a class="headerlink" href="#agreed-api" 
title="Permanent link">&para;</a></h1>
 <div class="codehilite"><pre><span class="err">@</span><span 
class="n">Retention</span><span class="p">(</span><span 
class="n">RetentionPolicy</span><span class="p">.</span><span 
class="n">RUNTIME</span><span class="p">)</span>
 <span class="err">@</span><span class="n">Target</span><span 
class="p">(</span><span class="n">ElementType</span><span 
class="p">.</span><span class="n">PARAMETER</span><span class="p">)</span>
 <span class="err">@</span><span class="n">Documented</span>
@@ -425,16 +436,16 @@
 </pre></div>
 
 
-<h1 id="under-discussion">Under discussion</h1>
+<h1 id="under-discussion">Under discussion<a class="headerlink" 
href="#under-discussion" title="Permanent link">&para;</a></h1>
 <ul>
 <li>Exception Handlers</li>
 <li>Entry into the Exception Handling system</li>
 </ul>
-<h2 id="apispi">API/SPI</h2>
-<h1 id="use-cases">Use-cases</h1>
-<h2 id="fire-and-observe-exceptions">Fire and observe exceptions</h2>
+<h2 id="apispi">API/SPI<a class="headerlink" href="#apispi" title="Permanent 
link">&para;</a></h2>
+<h1 id="use-cases">Use-cases<a class="headerlink" href="#use-cases" 
title="Permanent link">&para;</a></h1>
+<h2 id="fire-and-observe-exceptions">Fire and observe exceptions<a 
class="headerlink" href="#fire-and-observe-exceptions" title="Permanent 
link">&para;</a></h2>
 <p>An exception happens either in some business logic or from the container 
(maybe a session timed out or something like that). Developers need a simple, 
easy to use way to handle exceptions in a uniform way. They also need to be 
able to tell, after exception handling, if the exception was actually handled 
(a handler was found for the particular exception type or super type) or if it 
needs to be bubbled up to a higher level.</p>
-<h3 id="scenario">Scenario</h3>
+<h3 id="scenario">Scenario<a class="headerlink" href="#scenario" 
title="Permanent link">&para;</a></h3>
 <div class="codehilite"><pre><span class="n">Business</span> <span 
class="n">method</span> <span class="n">using</span> <span class="k">try</span> 
<span class="o">/</span> <span class="k">catch</span>
 <span class="n">public</span> <span class="n">void</span> <span 
class="n">myBusinessMethod</span><span class="p">(...)</span> <span 
class="p">{</span>
     <span class="k">try</span> <span class="p">{</span>
@@ -466,10 +477,10 @@
 </pre></div>
 
 
-<h1 id="message-module-draft">Message module draft</h1>
-<h1 id="features-to-merge">Features to merge</h1>
+<h1 id="message-module-draft">Message module draft<a class="headerlink" 
href="#message-module-draft" title="Permanent link">&para;</a></h1>
+<h1 id="features-to-merge">Features to merge<a class="headerlink" 
href="#features-to-merge" title="Permanent link">&para;</a></h1>
 <p>original list: https://issues.apache.org/jira/browse/DELTASPIKE-119</p>
-<h2 id="part-1">Part 1</h2>
+<h2 id="part-1">Part 1<a class="headerlink" href="#part-1" title="Permanent 
link">&para;</a></h2>
 <p>|| Feature || Comments || Objections || Discussion finished
 | Basic API |  |  | (+) |
 | Serializable messages | | not compatible with type-safe messages | |
@@ -482,7 +493,7 @@
 | message interpolator | | | (+) |
 | locale resolver | | | (+) due to type-safe messages it changed a bit - we 
have to re-visit it |
 | type safe messages | | | (+) |</p>
-<h2 id="part-2">Part 2</h2>
+<h2 id="part-2">Part 2<a class="headerlink" href="#part-2" title="Permanent 
link">&para;</a></h2>
 <p>This part depends on decissions of part 1.</p>
 <p>|| Feature || Comments || Objections || Discussion finished
 | el support (= el interpolation) | | | |
@@ -496,7 +507,7 @@
 | inline translated type safe messages | | | |
 | pluralizer system for message i18n | | | |
 | static helpers for simple messages | | | |</p>
-<h2 id="part-3">Part 3</h2>
+<h2 id="part-3">Part 3<a class="headerlink" href="#part-3" title="Permanent 
link">&para;</a></h2>
 <p>This part depends on the planned integration with other technologies like 
JSF, BV,...</p>
 <p>|| Feature || Comments || Objections || Discussion finished
 | add message to the "current" context | | | |
@@ -511,12 +522,21 @@
 | ability to hook Bean Validation messages into same infrastructure | needs 
clarification - reason: ConstraintViolation#getMessage returns a string | | |
 | ability to hook JSF validation messages into same infrastructure | see 
"current" context | | |
 | messages surviving multiple http redirects | | | |</p>
-<h2 id="part-4">Part 4</h2>
+<h2 id="part-4">Part 4<a class="headerlink" href="#part-4" title="Permanent 
link">&para;</a></h2>
 <p>This part contains features for integrating 3rd party libraries.</p>
-<p>|| Feature || Comments || Objections || Discussion finished
-| support joda-time dates | | | |</p>
-<h1 id="agreed-api_1">Agreed API</h1>
-<h2 id="basic-api">Basic API</h2>
+<table class="table">
+<thead>
+<tr>
+<th></th>
+<th>Feature</th>
+<th></th>
+<th>Comments</th>
+</tr>
+</thead>
+<tbody></tbody>
+</table>
+<h1 id="agreed-api_1">Agreed API<a class="headerlink" href="#agreed-api_1" 
title="Permanent link">&para;</a></h1>
+<h2 id="basic-api">Basic API<a class="headerlink" href="#basic-api" 
title="Permanent link">&para;</a></h2>
 <div class="codehilite"><pre><span class="cm">/**</span>
 <span class="cm"> * Basic interface for all message-types</span>
 <span class="cm"> */</span>
@@ -570,8 +590,8 @@
 </pre></div>
 
 
-<h1 id="api-under-discussion-part-1">API under discussion - Part 1</h1>
-<h2 id="message-interface">Message Interface</h2>
+<h1 id="api-under-discussion-part-1">API under discussion - Part 1<a 
class="headerlink" href="#api-under-discussion-part-1" title="Permanent 
link">&para;</a></h1>
+<h2 id="message-interface">Message Interface<a class="headerlink" 
href="#message-interface" title="Permanent link">&para;</a></h2>
 <div class="codehilite"><pre><span class="cm">/**</span>
 <span class="cm"> * Basic interface for all message-types</span>
 <span class="cm"> */</span>
@@ -599,7 +619,7 @@
 </pre></div>
 
 
-<h2 id="localizable">Localizable</h2>
+<h2 id="localizable">Localizable<a class="headerlink" href="#localizable" 
title="Permanent link">&para;</a></h2>
 <div class="codehilite"><pre><span class="cm">/**</span>
 <span class="cm"> * Classes which implement it can provide the message-text 
based on the given {@link MessageContext}</span>
 <span class="cm"> */</span>
@@ -614,7 +634,7 @@
 </pre></div>
 
 
-<h2 id="messageinterpolator">MessageInterpolator</h2>
+<h2 id="messageinterpolator">MessageInterpolator<a class="headerlink" 
href="#messageinterpolator" title="Permanent link">&para;</a></h2>
 <div class="codehilite"><pre><span class="cm">/**</span>
 <span class="cm"> * Implementations are responsible to replace placeholders in 
a message with the final value</span>
 <span class="cm"> */</span>
@@ -636,7 +656,7 @@
 </pre></div>
 
 
-<h2 id="messageresolver">MessageResolver</h2>
+<h2 id="messageresolver">MessageResolver<a class="headerlink" 
href="#messageresolver" title="Permanent link">&para;</a></h2>
 <div class="codehilite"><pre><span class="cm">/**</span>
 <span class="cm"> * Implementations have to resolve the text stored for a 
given key in the message-source they are aware of</span>
 <span class="cm"> */</span>
@@ -657,7 +677,7 @@
 </pre></div>
 
 
-<h2 id="localeresolver">LocaleResolver</h2>
+<h2 id="localeresolver">LocaleResolver<a class="headerlink" 
href="#localeresolver" title="Permanent link">&para;</a></h2>
 <div class="codehilite"><pre><span class="cm">/**</span>
 <span class="cm"> * Implementations have to provide the current locale</span>
 <span class="cm"> */</span>
@@ -671,7 +691,7 @@
 </pre></div>
 
 
-<h2 id="messagecontext">MessageContext</h2>
+<h2 id="messagecontext">MessageContext<a class="headerlink" 
href="#messagecontext" title="Permanent link">&para;</a></h2>
 <div class="codehilite"><pre><span class="cm">/**</span>
 <span class="cm"> * Central context for handling messages</span>
 <span class="cm"> */</span>
@@ -714,7 +734,7 @@
 </pre></div>
 
 
-<h2 id="messagecontextconfig">MessageContextConfig</h2>
+<h2 id="messagecontextconfig">MessageContextConfig<a class="headerlink" 
href="#messagecontextconfig" title="Permanent link">&para;</a></h2>
 <div class="codehilite"><pre><span class="cm">/**</span>
 <span class="cm"> * Config for customizing a {@link MessageContext}</span>
 <span class="cm"> */</span>
@@ -783,17 +803,17 @@
 
 
 <p># Security Module draft</p>
-<h1 id="agreed-api_2">Agreed API</h1>
+<h1 id="agreed-api_2">Agreed API<a class="headerlink" href="#agreed-api_2" 
title="Permanent link">&para;</a></h1>
 <ul>
 <li>@Secured</li>
 <li>@SecurityBindingType</li>
 <li>AccessDecisionVoter</li>
 <li>SecurityStrategy</li>
 </ul>
-<h1 id="agreed-api-and-spi-of-part-1">Agreed API and SPI of Part 1</h1>
+<h1 id="agreed-api-and-spi-of-part-1">Agreed API and SPI of Part 1<a 
class="headerlink" href="#agreed-api-and-spi-of-part-1" title="Permanent 
link">&para;</a></h1>
 <p>commit: 1a2c7ffd0d0a1ad3dea34515a54958f0a6ce2932</p>
-<h2 id="api">API</h2>
-<h3 id="identity">Identity</h3>
+<h2 id="api">API<a class="headerlink" href="#api" title="Permanent 
link">&para;</a></h2>
+<h3 id="identity">Identity<a class="headerlink" href="#identity" 
title="Permanent link">&para;</a></h3>
 <p>Session scoped result of the authentication process.</p>
 <div class="codehilite"><pre><span class="n">public</span> <span 
class="n">interface</span> <span class="n">Identity</span> <span 
class="n">extends</span> <span class="n">Serializable</span>
 <span class="p">{</span>
@@ -813,7 +833,7 @@
 </pre></div>
 
 
-<h3 id="user">User</h3>
+<h3 id="user">User<a class="headerlink" href="#user" title="Permanent 
link">&para;</a></h3>
 <p>Depending on further use-cases it can be refactored to an interface</p>
 <p>The id is an unique identifier for an user. It isn't defined if it is an 
internal identifier or an identifier known by the user (like the user-name).
 If users login e.g. via their e-mail address, it's possible to lookup an 
internal id in a custom implementation of {{LoginCredential}} or a bean which 
is in between (and {{LoginCredential}} doesn't get called directly in the 2nd 
case).</p>
@@ -837,7 +857,7 @@ If users login e.g. via their e-mail add
 </pre></div>
 
 
-<h3 id="credential">Credential</h3>
+<h3 id="credential">Credential<a class="headerlink" href="#credential" 
title="Permanent link">&para;</a></h3>
 <p>Credential is a holder for the "secret key" like a password.</p>
 <div class="codehilite"><pre><span class="n">public</span> <span 
class="n">interface</span> <span class="n">Credential</span><span 
class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span>
 <span class="p">{</span>
@@ -846,7 +866,7 @@ If users login e.g. via their e-mail add
 </pre></div>
 
 
-<h3 id="logincredential-former-credentials">LoginCredential (former 
Credentials)</h3>
+<h3 id="logincredential-former-credentials">LoginCredential (former 
Credentials)<a class="headerlink" href="#logincredential-former-credentials" 
title="Permanent link">&para;</a></h3>
 <p>Request scoped holder for the authentication process.</p>
 <p>[TODO] we need a better name for it</p>
 <ul>
@@ -870,7 +890,7 @@ If users login e.g. via their e-mail add
 <p>}</p>
 </li>
 </ul>
-<h3 id="events">Events</h3>
+<h3 id="events">Events<a class="headerlink" href="#events" title="Permanent 
link">&para;</a></h3>
 <ul>
 <li>LoggedInEvent</li>
 <li>LoginFailedEvent</li>
@@ -880,8 +900,8 @@ If users login e.g. via their e-mail add
 <li>PreAuthenticateEvent</li>
 <li>PostAuthenticateEvent</li>
 </ul>
-<h2 id="spi">SPI</h2>
-<h3 id="authenticatorselector">AuthenticatorSelector</h3>
+<h2 id="spi">SPI<a class="headerlink" href="#spi" title="Permanent 
link">&para;</a></h2>
+<h3 id="authenticatorselector">AuthenticatorSelector<a class="headerlink" 
href="#authenticatorselector" title="Permanent link">&para;</a></h3>
 <p>Request scoped bean used to find the current {{Authenticator}} for the 
authentication process - e.g. to provide different login-types used by the same 
client (e.g. a component in an UI).</p>
 <p>[TODO] discuss default (internal) Authenticator if there is no custom 
implementation.</p>
 <div class="codehilite"><pre><span class="kr">public</span> <span 
class="kr">interface</span> <span class="nx">AuthenticatorSelector</span>
@@ -899,7 +919,7 @@ If users login e.g. via their e-mail add
 </pre></div>
 
 
-<h3 id="authenticator">Authenticator</h3>
+<h3 id="authenticator">Authenticator<a class="headerlink" 
href="#authenticator" title="Permanent link">&para;</a></h3>
 <p>Called by {{Identity}} and performs the final authentication based on the 
information in {{LoginCredential}} .</p>
 <div class="codehilite"><pre><span class="n">public</span> <span 
class="n">interface</span> <span class="n">Authenticator</span>
 <span class="p">{</span>
@@ -942,8 +962,8 @@ If users login e.g. via their e-mail add
 </pre></div>
 
 
-<h2 id="usage">Usage</h2>
-<h3 id="simple-loginlogout-by-example-java-se">Simple Login/Logout by Example 
(Java-SE)</h3>
+<h2 id="usage">Usage<a class="headerlink" href="#usage" title="Permanent 
link">&para;</a></h2>
+<h3 id="simple-loginlogout-by-example-java-se">Simple Login/Logout by Example 
(Java-SE)<a class="headerlink" href="#simple-loginlogout-by-example-java-se" 
title="Permanent link">&para;</a></h3>
 <div class="codehilite"><pre><span class="p">@</span><span 
class="n">ApplicationScoped</span>
 <span class="n">public</span> <span class="n">class</span> <span 
class="n">LoginBean</span>
 <span class="p">{</span>
@@ -1002,9 +1022,9 @@ If users login e.g. via their e-mail add
 </pre></div>
 
 
-<h1 id="under-discussion_1">Under discussion</h1>
-<h2 id="apispi_1">API/SPI</h2>
-<h3 id="packages">Packages</h3>
+<h1 id="under-discussion_1">Under discussion<a class="headerlink" 
href="#under-discussion_1" title="Permanent link">&para;</a></h1>
+<h2 id="apispi_1">API/SPI<a class="headerlink" href="#apispi_1" 
title="Permanent link">&para;</a></h2>
+<h3 id="packages">Packages<a class="headerlink" href="#packages" 
title="Permanent link">&para;</a></h3>
 <ul>
 <li>*/authentication</li>
 <li>*/authentication/events</li>
@@ -1012,14 +1032,14 @@ If users login e.g. via their e-mail add
 <li>*/authorization/annotation</li>
 <li>*/credential or */authentication/credential</li>
 </ul>
-<h2 id="part-1_1">Part 1</h2>
+<h2 id="part-1_1">Part 1<a class="headerlink" href="#part-1_1" 
title="Permanent link">&para;</a></h2>
 <p>|| Feature || Comments || Objections || Discussion finished ||
 | Login via Username/Password | | | (+) |
 | Logout | | | (+) |
 | Authentication API and SPI | Credentials vs Credential (one of it needs a 
better name) | | (+) |
 | Basic User/Identity API | | | (+) |
 | Duration of a valid authentication | ExpirationEvaluator SPI | | |</p>
-<h2 id="part-2_1">Part 2</h2>
+<h2 id="part-2_1">Part 2<a class="headerlink" href="#part-2_1" 
title="Permanent link">&para;</a></h2>
 <p>|| Feature || Comments || Objections || Discussion finished ||
 | Object level permission | | | |
 | Grant or revoke permissions | | | |
@@ -1029,7 +1049,7 @@ If users login e.g. via their e-mail add
 | User/Identity management | | | |
 | Password-Hash-Service | | | |
 | Group management | optional support for typ-safe groups/group-types | | |</p>
-<h2 id="part-3_1">Part 3</h2>
+<h2 id="part-3_1">Part 3<a class="headerlink" href="#part-3_1" 
title="Permanent link">&para;</a></h2>
 <p>|| Feature || Comments || Objections || Discussion finished ||
 | Support for deputies (see Impersonalization) | | | |
 | Privileges concept | | | |
@@ -1039,16 +1059,16 @@ If users login e.g. via their e-mail add
 | Identity Store SPI | | | |
 | Query API | | | |
 | Application roles | | | |</p>
-<h2 id="part-4_1">Part 4</h2>
+<h2 id="part-4_1">Part 4<a class="headerlink" href="#part-4_1" 
title="Permanent link">&para;</a></h2>
 <p>|| Feature || Comments || Objections || Discussion finished ||
 | Support of alternative authentication concepts | Extend the Authentication 
SPI | | |
 | Integration with  authentication concepts of (application-) servers | Extend 
the Authentication SPI | | |
 | Personalization | | | |
 | Alternatives for roles/groups | | | |
 | Permission for external applications | | | |</p>
-<h1 id="use-cases_1">Use-cases</h1>
-<h2 id="authentication">Authentication</h2>
-<h3 id="scenario_1">Scenario</h3>
+<h1 id="use-cases_1">Use-cases<a class="headerlink" href="#use-cases_1" 
title="Permanent link">&para;</a></h1>
+<h2 id="authentication">Authentication<a class="headerlink" 
href="#authentication" title="Permanent link">&para;</a></h2>
+<h3 id="scenario_1">Scenario<a class="headerlink" href="#scenario_1" 
title="Permanent link">&para;</a></h3>
 <p>The user must be able to log in by supplying a username and password</p>
 <p>Example JSF code:</p>
 <div class="codehilite"><pre><span class="n">Username</span><span 
class="p">:</span> <span class="o">&lt;</span><span class="n">h</span><span 
class="p">:</span><span class="n">inputText</span> <span 
class="n">value</span><span class="p">=</span>&quot;#<span 
class="p">{</span><span class="n">credentials</span><span 
class="p">.</span><span class="n">username</span><span 
class="p">}</span>&quot;<span class="o">/&gt;</span>
@@ -1057,14 +1077,14 @@ If users login e.g. via their e-mail add
 </pre></div>
 
 
-<h3 id="scenario_2">Scenario</h3>
+<h3 id="scenario_2">Scenario<a class="headerlink" href="#scenario_2" 
title="Permanent link">&para;</a></h3>
 <p>The user must be able to log out</p>
 <p>Example JSF codee</p>
 <div class="codehilite"><pre><span class="o">&lt;</span><span 
class="n">h</span><span class="p">:</span><span class="n">commandButton</span> 
<span class="n">value</span><span class="p">=</span>&quot;<span 
class="n">LOGOUT</span>&quot; <span class="n">action</span><span 
class="p">=</span>&quot;#<span class="p">{</span><span 
class="n">identity</span><span class="p">.</span><span 
class="n">logout</span><span class="p">}</span>&quot;<span 
class="o">/&gt;</span>
 </pre></div>
 
 
-<h3 id="scenario_3">Scenario</h3>
+<h3 id="scenario_3">Scenario<a class="headerlink" href="#scenario_3" 
title="Permanent link">&para;</a></h3>
 <p>The developer must be able to easily implement their own custom 
authentication logic using a provided SPI</p>
 <p>Example</p>
 <div class="codehilite"><pre><span class="n">public</span> <span 
class="n">class</span> <span class="n">SimpleAuthenticator</span> <span 
class="n">extends</span> <span class="n">BaseAuthenticator</span> <span 
class="n">implements</span> <span class="n">Authenticator</span> <span 
class="p">{</span>
@@ -1086,12 +1106,12 @@ If users login e.g. via their e-mail add
 
 
 <p>{code}</p>
-<h3 id="scenario_4">Scenario</h3>
+<h3 id="scenario_4">Scenario<a class="headerlink" href="#scenario_4" 
title="Permanent link">&para;</a></h3>
 <p>It should be possible to provide an optional password service to create a 
password-hash based on the given password which will be stored instead of the 
real password.
 Maybe there should be different default implementations (provided via 
qualifiers).</p>
-<h3 id="scenario_5">Scenario</h3>
+<h3 id="scenario_5">Scenario<a class="headerlink" href="#scenario_5" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to authenticate application users stored inside 
corporate LDAP server.</p>
-<h3 id="scenario_6">Scenario</h3>
+<h3 id="scenario_6">Scenario<a class="headerlink" href="#scenario_6" 
title="Permanent link">&para;</a></h3>
 <p>The developer must be able to easily support alternative authentication 
providers, such as those supporting services such as OpenID or token based 
authentication. Those can be more complex then just “username/password” 
scenario and require redirects to or communication with specific external ISP 
(Identity Service Provider)</p>
 <p>Examples:</p>
 <ul>
@@ -1108,7 +1128,7 @@ For some of those technologies where aut
 Ability to implement own authenticator that have access to IDM and 
Securtiy/Permissions API in it.
 Provide automatic mapping between attributes returned by the Identity 
provider, and attributes stored in the local Identity store.
 Allow authentication from alternative view technologies, (i.e. AJAX)</p>
-<h3 id="scenario_7">Scenario</h3>
+<h3 id="scenario_7">Scenario<a class="headerlink" href="#scenario_7" 
title="Permanent link">&para;</a></h3>
 <p>The user must be able to authenticate automatically using a “Remember 
Me” feature, based on a unique cookie value stored by the user’s browser.  
For authentication performed in this manner, it must be also possible for the 
developer to configure a validation policy, which determines whether the user 
is required to provide their actual credentials for critical application 
operations such as changing passwords or e-mail address, placing orders, 
etc.</p>
 <p>The validation policy should also determine how long the validation window 
lasts, with some possible options being:</p>
 <ul>
@@ -1116,18 +1136,18 @@ Allow authentication from alternative vi
 <li>Validated for X minutes</li>
 <li>Validated until end of session</li>
 </ul>
-<h3 id="scenario_8">Scenario</h3>
+<h3 id="scenario_8">Scenario<a class="headerlink" href="#scenario_8" 
title="Permanent link">&para;</a></h3>
 <p>The developer must be able to easily integrate with AS security layer 
(JAAS/JAAC). Ideally by plugging DeltaSpike security into LoginModule stack.</p>
-<h2 id="impersonalization">Impersonalization</h2>
-<h3 id="scenario_9">Scenario</h3>
+<h2 id="impersonalization">Impersonalization<a class="headerlink" 
href="#impersonalization" title="Permanent link">&para;</a></h2>
+<h3 id="scenario_9">Scenario<a class="headerlink" href="#scenario_9" 
title="Permanent link">&para;</a></h3>
 <p>Administrator needs to verify assigned access, applied changes or exposed 
resources for specific user. He authenticates “as a user” or access 
application imitating his identity - without knowing his password.</p>
 <p>Examples:</p>
 <ul>
 <li>Facebook, see your profile as user 'bob'</li>
 <li>Mary is away from the office and someone needs to execute something on her 
behalf</li>
 </ul>
-<h2 id="authorization">Authorization</h2>
-<h3 id="scenario_10">Scenario</h3>
+<h2 id="authorization">Authorization<a class="headerlink" 
href="#authorization" title="Permanent link">&para;</a></h2>
+<h3 id="scenario_10">Scenario<a class="headerlink" href="#scenario_10" 
title="Permanent link">&para;</a></h3>
 <p>The developer must be able to control which elements of the user interface 
are displayed to the user based on the user's privilege level</p>
 <p>Example JSF code:</p>
 <div class="codehilite"><pre><span class="nt">&lt;div</span> <span 
class="na">class=</span><span class="s">&quot;menu&quot;</span><span 
class="nt">&gt;</span>
@@ -1136,7 +1156,7 @@ Allow authentication from alternative vi
 </pre></div>
 
 
-<h3 id="scenario_11">Scenario</h3>
+<h3 id="scenario_11">Scenario<a class="headerlink" href="#scenario_11" 
title="Permanent link">&para;</a></h3>
 <p>The developer must be able to control which elements of the user interface 
are displayed to the user based on their assigned permissions</p>
 <p>Example JSF code:</p>
 <div class="codehilite"><pre><span class="nt">&lt;table</span> <span 
class="na">class=</span><span class="s">&quot;customers&quot;</span><span 
class="nt">&gt;</span>
@@ -1151,20 +1171,20 @@ Allow authentication from alternative vi
 </pre></div>
 
 
-<h3 id="scenario_12">Scenario</h3>
+<h3 id="scenario_12">Scenario<a class="headerlink" href="#scenario_12" 
title="Permanent link">&para;</a></h3>
 <p>Sometimes developer may not have available instance of resource, which he 
wants to protect. It may be useful to ask for permission without need to obtain 
object from DB. It might be useful to have method: 
identity.hasPermission(String resourceType, String resourceId, String 
permission) in addition to current identity.hasPermission(Object resource, 
String permission)</p>
 <p>Example JSF code:</p>
 <div class="codehilite"><pre> <span class="o">&lt;</span><span 
class="n">h</span><span class="p">:</span><span class="n">commandButton</span> 
<span class="n">value</span><span class="p">=</span>&quot;<span 
class="n">Edit</span> <span class="n">page</span>&quot; <span 
class="n">rendered</span><span class="p">=</span>&quot;#<span 
class="p">{</span><span class="n">identity</span><span class="p">.</span><span 
class="n">hasPermission</span><span class="p">(</span><span 
class="s">&#39;PAGE&#39;</span><span class="p">,</span> <span 
class="s">&#39;AcmePage&#39;</span><span class="p">,</span> <span 
class="s">&#39;EDIT&#39;</span><span class="p">)}</span>&quot; <span 
class="n">action</span><span class="p">=</span>&quot;<span 
class="p">...</span>&quot;<span class="o">/&gt;</span>
 </pre></div>
 
 
-<h3 id="scenario_13">Scenario</h3>
+<h3 id="scenario_13">Scenario<a class="headerlink" href="#scenario_13" 
title="Permanent link">&para;</a></h3>
 <p>The developer must be able to restrict method access based on the user's 
privilege level.
 Example:</p>
 <p>(Already addressed with typesafe security annotations, e.g. 
@SecurityBindingType)</p>
-<h3 id="scenario_14">Scenario</h3>
+<h3 id="scenario_14">Scenario<a class="headerlink" href="#scenario_14" 
title="Permanent link">&para;</a></h3>
 <p>The framework must provide a system for resolving object permissions, and 
the developer must have access to an SPI for easily providing their own custom 
permission resolver logic.</p>
-<h3 id="scenario_15">Scenario</h3>
+<h3 id="scenario_15">Scenario<a class="headerlink" href="#scenario_15" 
title="Permanent link">&para;</a></h3>
 <p>The user (with the necessary privileges) must be able assign permissions to 
individual objects within the application’s business domain (i.e. ACL style 
permissions) and have these permissions persisted.  These permissions 
should:</p>
 <ul>
 <li>Be assignable to either the individual user, a group, or a role</li>
@@ -1172,9 +1192,9 @@ Example:</p>
 <li>Have configurable identifier policies, i.e. Entity beans will use an 
identifier based on the primary key value</li>
 <li>Have a configurable permission store, i.e. it must be possible to store 
permissions in a database using JPA, etc.</li>
 </ul>
-<h3 id="scenario_16">Scenario</h3>
+<h3 id="scenario_16">Scenario<a class="headerlink" href="#scenario_16" 
title="Permanent link">&para;</a></h3>
 <p>Further to the previous requirement, there must be an API for managing 
persistent permissions.  Operations performed by the user on this API (such as 
granting or revoking permissions to/from other users) may be subjected to an 
additional security check.</p>
-<h3 id="scenario_17">Scenario</h3>
+<h3 id="scenario_17">Scenario<a class="headerlink" href="#scenario_17" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to perform authorization checks based on information 
stored in corporate LDAP server or dedicated database. This external store 
contains information about all company employees and maps hierarchy including 
groups present in the organization with information about their members.</p>
 <p>Company has a Windows domain and whole security model build around 
structure of group of users stored in Microsoft Active Directory. Application 
developer needs to integrate security with this information.
 Examples:</p>
@@ -1185,9 +1205,9 @@ Examples:</p>
 <li>Restrict adding new members to a  group only for its administrator</li>
 <li>identityManager.hasRole(“administrator”, “john”, 
“/some/specific/group”);</li>
 </ul>
-<h3 id="scenario_18">Scenario</h3>
+<h3 id="scenario_18">Scenario<a class="headerlink" href="#scenario_18" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to control access to application resources based on 
structure of groups and user roles</p>
-<h3 id="scenario_19">Scenario</h3>
+<h3 id="scenario_19">Scenario<a class="headerlink" href="#scenario_19" 
title="Permanent link">&para;</a></h3>
 <p>Web application has a number of resources that needs to be secured with 
more fine grained security model. Invoking operations on a given resource needs 
to be restricted with a given permission. User can inherit set of permissions 
to the given resource from group to which he belongs or from role he posses.</p>
 <p>Examples:</p>
 <ul>
@@ -1198,8 +1218,8 @@ Examples:</p>
 *User belongs to group “/operators/content_creator”. Therefore he inherits 
a set of permissions (CREATE, EDIT, REMOVE) to add new content on specified 
page in the application.</li>
 </ul>
 <p>Requirements:</p>
-<h2 id="permissions-model">Permissions model</h2>
-<h3 id="scenario_20">Scenario</h3>
+<h2 id="permissions-model">Permissions model<a class="headerlink" 
href="#permissions-model" title="Permanent link">&para;</a></h2>
+<h3 id="scenario_20">Scenario<a class="headerlink" href="#scenario_20" 
title="Permanent link">&para;</a></h3>
 <p>Application has a structure of resources. Permissions assigned to user for 
a given resource in the tree are inherited by other resources. User is able to 
edit all sub resources based on permissions assigned to parent resource.</p>
 <p>Example:</p>
 <ul>
@@ -1207,7 +1227,7 @@ Examples:</p>
 <li>User assigned to manage specific page should also be able to manage all 
sub pages.</li>
 <li>Permissions are inherited.</li>
 </ul>
-<h3 id="scenario_21">Scenario</h3>
+<h3 id="scenario_21">Scenario<a class="headerlink" href="#scenario_21" 
title="Permanent link">&para;</a></h3>
 <p>Application persists a structure of groups and users that have roles in 
those groups. Application developer needs to have some permissions related to 
one group be inherited by their sub groups.</p>
 <p>Example:</p>
 <ul>
@@ -1215,14 +1235,14 @@ Examples:</p>
 <li>Group “/organization/it_dept” has assigned READ and CREATE permission 
associated with “IT Security Event Logs”  page in the application.</li>
 <li>All users with role in “/organizaiton/it_dept” will be able to read 
“Corporate news” page because READ permission will be inherited from 
“/organization” group.</li>
 </ul>
-<h3 id="scenario_22">Scenario</h3>
+<h3 id="scenario_22">Scenario<a class="headerlink" href="#scenario_22" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to define several types of contexts in which user is 
connected with a given group to enable flexible authorization of different 
types of performed operations</p>
 <p>Example:</p>
 <p>John is an “administrator” of “/communities/base_jumping” group and 
can perform administrative tasks on resources connected with this group
 John is a “member” of “/communities/base_jumping” group and he can 
access and read resources connected with this group
 John is a “content validator” of “/communities/base_jumping” group and 
he will be asked to authorize any new content on pages related to this group 
before it gets published.</p>
 <p>In all examples described above single group can have several users with 
same role.</p>
-<h4 
id="this-specifically-can-be-addressed-with-the-domain-acl-type-approach-as-prototyped-in-seam-security">This
 specifically can be addressed with the Domain ACL type approach, as prototyped 
in Seam Security:</h4>
+<h4 
id="this-specifically-can-be-addressed-with-the-domain-acl-type-approach-as-prototyped-in-seam-security">This
 specifically can be addressed with the Domain ACL type approach, as prototyped 
in Seam Security:<a class="headerlink" 
href="#this-specifically-can-be-addressed-with-the-domain-acl-type-approach-as-prototyped-in-seam-security"
 title="Permanent link">&para;</a></h4>
 <p>One of the biggest problems of Java web app security to date, and what will 
also be a problem in our framework, is that Java EE, Seam Security have not 
been able to satisfy a very common type of Authentication, domain 
authentication, and have focused solely on global role-based security 
authorisation:</p>
 <p>E.g: Global authentication is "Is the user an Admin of the application," as 
opposed to domain authentication, which asks, "Is the user an Admin of this 
Domain Object,"</p>
 <p>Developers typically have to implement their own security system (via 
direct method calls, or etc...) for this type of business logic.</p>
@@ -1258,14 +1278,14 @@ John is a “content validator”
 
 
 <p>Note that the @Project annotation is not a CDI bean Qualifier / Stereotype 
annotation, it is a method parameter security binding annotation that tells 
Seam Security to use the value of the Project passed to the method call in the 
security binding check itself.</p>
-<h3 id="scenario_23">Scenario</h3>
+<h3 id="scenario_23">Scenario<a class="headerlink" href="#scenario_23" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to define single user or group that will serve as super 
users (aka root users. Those will have any available permissions.</p>
 <p>Example:</p>
 <ul>
 <li>identity.isRootUser()</li>
 <li>identityManager.getRootUsers();</li>
 </ul>
-<h3 id="scenario_24">Scenario</h3>
+<h3 id="scenario_24">Scenario<a class="headerlink" href="#scenario_24" 
title="Permanent link">&para;</a></h3>
 <p>Application needs to authorize access based on inherited group 
membership.</p>
 <p>Example:</p>
 <p>Access to information about new trips is restricted to members of 
“/communities/hiking” group
@@ -1274,13 +1294,13 @@ On the other hand, access to information
 <p>Example: You can configure that info about classic trips is available for 
“/communities/hiking*” which would mean /communities/hiking and all it’s 
subgroups. On the other hand info about climbing trips is available only for 
individual groups “/communities/hiking” and 
“/communities/hiking/seniors” as we don’t want to have group inheritance 
here.
 For this climbing usecase, it may be useful to DENY permission available from 
parent groups.</p>
 <p>Example: You can configure that info about climbing trips will be available 
for “/communities/hiking*” but permission is denied for members for 
“/communites/hiking/juniors”. In this case, groups 
“/commuinites/hiking”, “/communities/hiking/instructors”, 
“/communities/hiking/seniors” will have permission. Members of group 
“/communities/hiking/juniors” won’t hav permission.</p>
-<h3 id="scenario_25">Scenario</h3>
+<h3 id="scenario_25">Scenario<a class="headerlink" href="#scenario_25" 
title="Permanent link">&para;</a></h3>
 <p>The developer may want to have permissions based on other criterias than 
only roles/groups. Some of these requirements can be handled by XACML 
integration mentioned below.</p>
 <ul>
 <li>I want page "hobby" to be accessible for employees only after 6pm, to 
enforce that my employees won't go to hobby page during their working time.</li>
 <li>I want forum portlet with "Retiree forum" to be accessible only for users 
older than 60 years. Only exceptions can be "/platform/administrators" group, 
whose members can access page everytime regardless of their age.</li>
 </ul>
-<h3 id="scenario_26">Scenario</h3>
+<h3 id="scenario_26">Scenario<a class="headerlink" href="#scenario_26" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to integrate application with more advanced security 
resolution mechanisms.</p>
 <p>Examples:</p>
 <ul>
@@ -1290,10 +1310,10 @@ For this climbing usecase, it may be use
 </ul>
 <p>Requirements:</p>
 <p>Well thought API/SPI that doesn’t limit such integration.</p>
-<h3 id="scenario_27">Scenario</h3>
+<h3 id="scenario_27">Scenario<a class="headerlink" href="#scenario_27" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to expose part of application features to be accessible 
by external services and authorize their access.</p>
-<h2 id="delegated-administration">Delegated Administration</h2>
-<h3 id="scenario_28">Scenario</h3>
+<h2 id="delegated-administration">Delegated Administration<a 
class="headerlink" href="#delegated-administration" title="Permanent 
link">&para;</a></h2>
+<h3 id="scenario_28">Scenario<a class="headerlink" href="#scenario_28" 
title="Permanent link">&para;</a></h3>
 <p>Web application has a number of user groups or resources that needs to be 
managed. It is desired that management permission to only part of those are 
delegated to specific user</p>
 <p>Examples:</p>
 <ul>
@@ -1304,9 +1324,9 @@ For this climbing usecase, it may be use
 </ul>
 <p>Requirements:</p>
 <p>Advanced enough security and identity model to map required permissions</p>
-<h2 id="identity-management-idm">Identity Management (IDM)</h2>
+<h2 id="identity-management-idm">Identity Management (IDM)<a 
class="headerlink" href="#identity-management-idm" title="Permanent 
link">&para;</a></h2>
 <p>All use cases with strong focus around concepts and operations on User, 
Group and Role</p>
-<h3 id="scenario_29">Scenario</h3>
+<h3 id="scenario_29">Scenario<a class="headerlink" href="#scenario_29" 
title="Permanent link">&para;</a></h3>
 <p>Application needs to expose basic user management capabilities. To register 
new user, edit profile and remove old users. Basic provisioning and management 
API for user, group and role.</p>
 <p>Examples:</p>
 <div class="codehilite"><pre><span class="n">User</span> <span 
class="n">johnUser</span> <span class="p">=</span> <span 
class="n">identityManager</span><span class="p">.</span><span 
class="n">createUser</span><span class="p">(</span>“<span 
class="n">john</span><span class="p">);</span>
@@ -1317,7 +1337,7 @@ For this climbing usecase, it may be use
 </pre></div>
 
 
-<h3 id="scenario_30">Scenario</h3>
+<h3 id="scenario_30">Scenario<a class="headerlink" href="#scenario_30" 
title="Permanent link">&para;</a></h3>
 <p>Application needs to enable groups management capabilities. Administrators 
must be able to map organization structure in the application to be able to set 
proper security restrictions</p>
 <p>Examples:</p>
 <div class="codehilite"><pre><span class="n">Group</span> <span 
class="n">parisOffice</span> <span class="p">=</span> <span 
class="n">identityManager</span><span class="p">.</span><span 
class="n">createGroup</span><span class="p">(</span>“<span 
class="n">paris</span>”<span class="p">,</span> “<span 
class="o">/</span><span class="k">global</span><span class="o">/</span><span 
class="n">offices</span><span class="o">/</span><span 
class="n">emea</span><span class="o">/</span>”<span class="p">);</span>
@@ -1327,7 +1347,7 @@ For this climbing usecase, it may be use
 </pre></div>
 
 
-<h3 id="scenario_31">Scenario</h3>
+<h3 id="scenario_31">Scenario<a class="headerlink" href="#scenario_31" 
title="Permanent link">&para;</a></h3>
 <p>Application needs to enable group based security that maps relationships 
from real organization structure. Therefore users need to be associated with 
specific groups in organization hierarchy and have defined roles in context of 
those groups</p>
 <p>Examples:</p>
 <div class="codehilite"><pre><span class="n">Group</span> <span 
class="n">itsec</span> <span class="p">=</span> <span 
class="n">identityManager</span><span class="p">.</span><span 
class="n">createGroup</span><span class="p">(</span>“<span 
class="n">itsec</span>”<span class="p">,</span> “<span 
class="o">/</span><span class="n">organization</span><span 
class="o">/</span><span class="n">engineering</span><span 
class="o">/</span><span class="n">security</span>”<span class="p">);</span>
@@ -1340,7 +1360,7 @@ For this climbing usecase, it may be use
 </pre></div>
 
 
-<h3 id="scenario_32">Scenario</h3>
+<h3 id="scenario_32">Scenario<a class="headerlink" href="#scenario_32" 
title="Permanent link">&para;</a></h3>
 <p>Application needs to expose capabilities to associate authenticated user 
with specific roles in application context.</p>
 <p>Examples:</p>
 <div class="codehilite"><pre><span class="n">identity</span><span 
class="p">.</span><span class="n">addApplicationRole</span><span 
class="p">(</span>“<span class="n">SuperUser</span>”<span 
class="p">);</span>
@@ -1348,23 +1368,23 @@ For this climbing usecase, it may be use
 </pre></div>
 
 
-<h3 id="scenario_33">Scenario</h3>
+<h3 id="scenario_33">Scenario<a class="headerlink" href="#scenario_33" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to query user, groups and roles in a way that will not 
affect performance. He needs to sync into database 500k user entries from 
corporate LDAP server and quite big group structure. Methods like 
identityManager.getAllUsers() will be performance bottlenecs. The developer 
needs to obtain pagainated and sorted results.</p>
 <p>Examples:</p>
 <div class="codehilite"><pre><span class="n">identityManager</span><span 
class="p">.</span><span class="n">createGroupQuery</span><span 
class="p">().</span><span class="n">setRelatedUser</span><span 
class="p">(</span>“<span class="n">john</span>”<span 
class="p">).</span><span class="n">setParentGroup</span><span 
class="p">(</span>“<span class="o">/</span><span 
class="n">offices</span>”<span class="p">).</span><span 
class="n">sort</span><span class="p">(</span><span class="n">true</span><span 
class="p">).</span><span class="n">setRange</span><span class="p">(</span><span 
class="n">Range</span><span class="p">.</span><span class="n">of</span><span 
class="p">(</span>0<span class="p">,</span>10<span class="p">)).</span><span 
class="n">execute</span><span class="p">();</span>
 </pre></div>
 
 
-<h3 id="scenario_34">Scenario</h3>
+<h3 id="scenario_34">Scenario<a class="headerlink" href="#scenario_34" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to query user by unique attribute (email) and group 
membership when “new user registration” form is submitted in the 
application.</p>
 <p>Examples:</p>
 <div class="codehilite"><pre><span class="n">identityManager</span><span 
class="p">.</span><span class="n">createUserQuery</span><span 
class="p">().</span><span class="n">setRelatedGroup</span><span 
class="p">(</span>“<span class="o">/</span><span 
class="n">employees</span>”<span class="p">).</span><span 
class="n">setAttributeFilter</span><span class="p">(</span>“<span 
class="n">personal</span><span class="p">.</span><span 
class="n">email</span>”<span class="p">,</span> <span 
class="n">values</span><span class="p">).</span><span 
class="n">setRange</span><span class="p">(</span><span 
class="n">Range</span><span class="p">.</span><span class="n">of</span><span 
class="p">(</span>0<span class="p">.</span>100<span class="p">));</span>
 </pre></div>
 
 
-<h3 id="scenario_35">Scenario</h3>
+<h3 id="scenario_35">Scenario<a class="headerlink" href="#scenario_35" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to persist user, group and role information in 
database. JPA implementation is his dream.</p>
-<h3 id="scenario_36">Scenario</h3>
+<h3 id="scenario_36">Scenario<a class="headerlink" href="#scenario_36" 
title="Permanent link">&para;</a></h3>
 <p>The developer want to give freedom to plug different type of identityStore 
into his application in the future. Not all identity store expose equal 
operations for pagination, sorting or querying by attributes. He needs to 
design his GUI so it can query underlying IdentityStore if specific operations 
are supported.</p>
 <p>Examples:</p>
 <div class="codehilite"><pre><span class="n">identityManager</span><span 
class="p">.</span><span class="n">getSupportedFeatures</span><span 
class="p">().</span><span class="n">isUserSortSupported</span><span 
class="p">();</span>
@@ -1372,8 +1392,8 @@ For this climbing usecase, it may be use
 </pre></div>
 
 
-<h2 id="events_1">Events</h2>
-<h3 id="scenario_37">Scenario</h3>
+<h2 id="events_1">Events<a class="headerlink" href="#events_1" 
title="Permanent link">&para;</a></h2>
+<h3 id="scenario_37">Scenario<a class="headerlink" href="#scenario_37" 
title="Permanent link">&para;</a></h3>
 <p>Application developer needs to add specific hooks for common IDM or 
Security operations</p>
 <p>Examples:</p>
 <p>Audit and logging for permission and IDM related changes or information 
resolution
@@ -1381,28 +1401,28 @@ Assigning specific permissions for every
 Synchronization based integration with LDAP. All changes to users and groups 
are synced back to external store. On specific event LDAP is queried for a 
changelog and based on that changes from external store are synced to the 
internal store.</p>
 <p>Requirements:</p>
 <p>Event API.</p>
-<h2 id="personalization">Personalization</h2>
+<h2 id="personalization">Personalization<a class="headerlink" 
href="#personalization" title="Permanent link">&para;</a></h2>
 <p>This is not fully related to security but it is tightly coupled with 
identity model that is already in place</p>
-<h3 id="scenario_38">Scenario</h3>
+<h3 id="scenario_38">Scenario<a class="headerlink" href="#scenario_38" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to let application users set their own locale. He also 
needs to set default ones per group of users. For case that user is member of 
more groups, we need to specify which group will have priority for determining 
the defaultLocale (or other attribute) for user. Some groups can be ignored.
 Examples:</p>
 <p>Group “/application_users” have attribute “defalutLocale”. All 
users with role “member” in this group inherit this attribute. Each user 
can override this value
 User is member of “/application_users” and “/partners” . Group 
“/application_users” has default locale “fr” and group “/partners” 
has default locale “en”. We assume that “/application_users” has bigger 
priority so defaultLocale of user will be “fr”.</p>
-<h3 id="scenario_39">Scenario</h3>
+<h3 id="scenario_39">Scenario<a class="headerlink" href="#scenario_39" 
title="Permanent link">&para;</a></h3>
 <p>The developer needs to let application users set their own skin in their 
application. He also needs to set default skins per group of users.
 Examples:</p>
 <p>Groups “/vendors”, “/partners” and “/employees” have different 
value of attribute “defaultSkin”. Their members inherit this attribute 
value.</p>
-<h2 id="ldap-or-external-identity-store-integration">LDAP or External Identity 
Store Integration</h2>
+<h2 id="ldap-or-external-identity-store-integration">LDAP or External Identity 
Store Integration<a class="headerlink" 
href="#ldap-or-external-identity-store-integration" title="Permanent 
link">&para;</a></h2>
 <p>Integrating external identity store is a common scenario for application 
developers. Most common case is corporate LDAP or MSAD hosting users in Windows 
Domain. However other custom solutions like Web Service or REST based services 
for IDM are often spotted in organizations.</p>
 <p>There are 3 ways such internal store can be integrated. At least “Direct 
Integration” and “Synchronization” scenarios need to be addressed</p>
-<h3 id="scenario-direct-integration">Scenario - Direct Integration</h3>
+<h3 id="scenario-direct-integration">Scenario - Direct Integration<a 
class="headerlink" href="#scenario-direct-integration" title="Permanent 
link">&para;</a></h3>
 <p>In such case application developer replaces default JPA based identity 
store implementation with custom one.</p>
 <p>Few limitations apply in such case. Different identity storage services 
(even LDAP) have certain limitations in compare to full blown IDM framework 
API. For example LDAP cannot flexibly store any type of attribute unless LDAP 
schema is extended - which is often not possible in the organization and 
restricted by administrators. Other example is no direct or easy mapping of 
roles - just simple notion if user is member of a group or not. Some of strict 
LDAP schema implementations doesn’t allow group without any member.</p>
 <p>Other limitation is typically less flexible query mechanism. For example in 
LDAP you cannot easily perform efficient query with multiple conditions that 
would be sorted and paginated. With flexible Query API and big number of 
identity entries in the store it is a rising issue. Implementing rich IDM 
API/SPI can easily create performance bottlenecks</p>
-<h3 id="scenario-identity-store-routing">Scenario - Identity Store Routing</h3>
+<h3 id="scenario-identity-store-routing">Scenario - Identity Store Routing<a 
class="headerlink" href="#scenario-identity-store-routing" title="Permanent 
link">&para;</a></h3>
 <p>In this scenario application developer implements routing to invoke methods 
on several identity stores and merge results. In simplest case part of user 
attributes (limited by LDAP schema) and information about user roles are kept 
in JPA implementation. Users and groups can be created in external store based 
on routing configuration.</p>
 <p>Limitations described in previous scenario still apply in this scenario. 
Additionally it is easy to introduce serious performance bottlenecks. For 
example If developer allows situation of having some users stored in database 
and some in LDAP then queries become non trival. Any kind of more complex query 
may involve retrieving all results from both sources, merging and applying sort 
and pagination in the second step. With 500k entries in directory it is 
impossible to perform such queries efficiently.</p>
-<h3 id="scenario-synchronization">Scenario - Synchronization</h3>
+<h3 id="scenario-synchronization">Scenario - Synchronization<a 
class="headerlink" href="#scenario-synchronization" title="Permanent 
link">&para;</a></h3>
 <p>In this scenario all identities are always kept in default JPA based 
identity store. All queries are performed on it. External identity store 
content is synchronized based on scheduled plan or event system. Many modern 
LDAP stores expose feature called “changelog”. It is possible to obtain 
small delta of frequent changes to apply.</p>
 <p>Still some operations like authentication are performed directly on 
external store. Reason is that modern authentication systems won’t expose 
password but just validatePassword type of operation.</p>
 <p>Examples:</p>
@@ -1419,7 +1439,7 @@ Examples:</p>
       <hr>
 
       <footer>
-        <p>Copyright © 2011-2014 The Apache Software Foundation, Licensed 
under the Apache License, Version 2.0.</p>
+        <p>Copyright © 2011-2015 The Apache Software Foundation, Licensed 
under the Apache License, Version 2.0.</p>
         <p>Apache and the Apache feather logo are trademarks of The Apache 
Software Foundation.</p>
       </footer>
 


Reply via email to