Im not using Shiro Servlet filter. My stacks -
1) Java webapp application. It has rest controller. It calls Shiro Authentication manager rest api. 2) Separately hosted Shiro Authentication Manager. This will do authentication and permission checks. This also has rest controller. Type of authentication - Implemented 2 types - JDBC realm and AD realm Thanks for you reply Brian. -- Sent from: http://shiro-developer.582600.n2.nabble.com/
