Strange, but could you provide a few more basic clarifications?
(i) Is the URL pattern case-sensitive in your case? Could you try with a larger /* and check if it works?
(ii) Could you check by configuring a specific user say 'developer' belonging to group 'developer' , map this role to access the secure resource, turn default principal-role mapping on , restart server and retry?
Thanks,
Nithya
[Message sent by forum member 'nitkal' ]
http://forums.java.net/jive/thread.jspa?messageID=373576