Hi I'm putting together a customer user manager for orion, extending com.evermind.security.AbstractUserManager, with UserWrapper and GroupWrapper classes implementing com.evermind.security.User and com.evermind.security.Group respectively.
Now HttpServletRequest.isUserInRole() used to call User.isMemberOf() back in the days of <= 1.4.0, this however does not seem to be the case anymore. isMemberOf() still gets called to satisfy the <security-constraint>s in web.xml. Looking at the example on orionsupport.com, three abstract methods are mentioned: protected boolean userExists( String username ); protected boolean checkPassword( String username, String password ); protected boolean inGroup( String username, String groupname ); It doesn't appear that HttpServletRequest.isUserInRole() gets trunked through to inGroup() nor do I see these three methods in any Orion interface definition ? Does anyone know how to fix this? Or how HttpServletRequest.isUserInRole() gets handled by Orion ? I've search the mailing list archive and it seems that other users have also encountered these problems but it never got sorted out ? Many thanks for any assistance, Peter
