Is there a reason not to use declarative security in the deployment descriptor for role based authorisation for each resource?
I'll be heading down this track soon and that's what I had wanted to do. Nick Faiz -----Original Message----- From: muzammil shahbaz [mailto:[EMAIL PROTECTED] Sent: Thursday, 9 October 2003 6:11 PM To: zzStruts Users Mailing List Subject: RE: Struts security Exactly!!! U got the point. That's what I use to handle security issues. Keep it up :-) ---------- From: Stefan Trcko [SMTP:[EMAIL PROTECTED] Sent: Thursday, October 09, 2003 12:57 PM To: [EMAIL PROTECTED] Cc: Struts Users Mailing List Subject: Re: Struts security <<File: ATT00006.txt>> --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

