Thanks guys, using roles with a namespacing convention seems like the best option. It might be worth thinking about roles getting Role and RoleResolver interfaces similar to what permissions have with Permission and PermissionResolver and then being able to do the same sort of wildcarding with roles as permissions allow.
-- View this message in context: http://shiro-user.582556.n2.nabble.com/Group-specific-roles-tp6335910p6336409.html Sent from the Shiro User mailing list archive at Nabble.com.
