> Just a quick follow-up. A permission is required to call
> Subject.getSubject; in my opinion, the EJB container should not
> grant that to the executing user code by default (unportable and
> potentially insecure).

You are of course correct.

And yes, jBoss does not grant that permission if the EJB security is turned
on.

/Rickard






--
--------------------------------------------------------------
To subscribe:        [EMAIL PROTECTED]
To unsubscribe:      [EMAIL PROTECTED]
Problems?:           [EMAIL PROTECTED]

Reply via email to