* Once authentication is done, how do you know
what security identity is now effective within the
session context for some bean?  Is that identity
just the "subject" used for the login?

* As the user (who has logged in) navigates through
a web application, how is the security identity propagated
(or sustained)?  [Note: I've read about how EJB defines
propagation of security contexts between beans -- is that
feature implemented in jBoss?]

Thanks,
Charlie




--
--------------------------------------------------------------
To subscribe:        [EMAIL PROTECTED]
To unsubscribe:      [EMAIL PROTECTED]
List Help?:          [EMAIL PROTECTED]

Reply via email to