users@glassfish.java.net

Security propagation with form based authentication

From: <glassfish_at_javadesktop.org>
Date: Tue, 14 Apr 2009 09:23:35 PDT

Hi...

I've a Web project communicating with an EJB project remotely (same GF, but remote EJB).
Each have same role mapping configured.

If I authenticate on the Web project with a CLIENT-CERT method, security groups are propagated to the EJB project.
But if I authenticate with a FORM method, only the principal identity is propagated.

Is it normal ? how to propagate security groups with form method ?

Note : All accesses are configured CONFIDENTIAL on both Web ad EJB projects.

Thank...
[Message sent by forum member 'kabhal' (kabhal)]

http://forums.java.net/jive/thread.jspa?messageID=342011