|
I think maybe I didn't make something clear.
I am using a java "application" client, NOT a web client. As such, I
cannot invalidate sessions, make posts, etc.
Orion seems to be written primarily as a web app
server, and I have seen very little information on using it as a direct
application server (in Orion literature or in the Oracle
OC4J docs.) Since very few people are using Orion in this way, I
guess I should expect to see a few bugs here and there. (I'm guessing that
this is an application-client specific issue.)
Anyway, I could be wrong in beleiving that the
problem is in stateless session beans... As Lachezar pointed out, it might
be in the InitialContext.
By the way, I saw this behavior in Orion 1.4.5 and
in the latest release, 1.5.2.
Any suggestions are appreciated,
Mike
|
- Security bug with application clients? Michael Jara
- RE: Security bug with application clients? elephantwalker
- Re: Security bug with application clients? Lachezar Dobrev
- RE: Security bug with application clients? Dvornikov Victor
- Re: Security bug with application clients? Michael Jara
- Re: Security bug with application clients? Tim Endres
- RE: Security bug with application clients? cybermaster
- RE: Security bug with application clients? Dvornikov Victor
