Could you provide more details like your descriptor files or annotations that you may have used to configure the roles? Is it that you are trying to access Method C using the role 'web' and it is being permitted though, 'web' role is not configured for this method?Are we understanding this right? Is there any servicefacade (your original post mentions one) being used anywhere here?
Thanks
Nithya
[Message sent by forum member 'nitkal' (nitkal)]
http://forums.java.net/jive/thread.jspa?messageID=329152