Hi

I'm putting together a customer user manager for orion, extending
com.evermind.security.AbstractUserManager, with UserWrapper and
GroupWrapper classes implementing com.evermind.security.User and
com.evermind.security.Group respectively. 

Now HttpServletRequest.isUserInRole() used to call User.isMemberOf()
back in the days of <= 1.4.0, this however does not seem to be the case
anymore. isMemberOf() still gets called to satisfy the
<security-constraint>s in web.xml. 

Looking at the example on orionsupport.com, three abstract methods are
mentioned:

protected boolean userExists( String username );
protected boolean checkPassword( String username, String password );
protected boolean inGroup( String username, String groupname );

It doesn't appear that HttpServletRequest.isUserInRole() gets trunked
through to inGroup() nor do I see these three methods in any Orion
interface definition ?

Does anyone know how to fix this? Or how
HttpServletRequest.isUserInRole() gets handled by Orion ?
I've search the mailing list archive and it seems that other users have
also encountered these problems but it never got sorted out ?

Many thanks for any assistance,
Peter




Reply via email to