Somehow this doesn't feel like an adequate response to the amount of effort you've obviously put in to your replies... but thank you, that confirms my suspicions. I've been doing this long enough to realise if something hurts, to stop doing it :)
My only disappointment is the reduced usefulness of the principal JSP tag, but I don't think it'll be difficult to roll my own wrapping the "get UserId from Principal and load User instance from the database". So I reckon I'll remove the User from my Principals collection and just use the UserId instead. Thanks for the help! James -- View this message in context: http://shiro-user.582556.n2.nabble.com/Updating-or-invalidating-Subject-Principals-tp6570762p6572395.html Sent from the Shiro User mailing list archive at Nabble.com.
