The JAAS login does not change the security association at the web container level such that forwarded request are done with that security context. The JAAS login affects calls to other secured resources like jms, ejbs, and jca. I have created a feature request to see if this is something we can provide support for in the future: http://jira.jboss.com/jira/browse/JBWEB-3
View the original post : http://www.jboss.org/index.html?module=bb&op=viewtopic&p=3857383#3857383 Reply to the post : http://www.jboss.org/index.html?module=bb&op=posting&mode=reply&p=3857383 ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://productguide.itmanagersjournal.com/ _______________________________________________ JBoss-user mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/jboss-user