users@glassfish.java.net

Re: JAAS and StatelessSession on GFv3.1

From: <glassfish_at_javadesktop.org>
Date: Wed, 02 Jun 2010 01:15:13 PDT

Dear Tim,

Do you known about from security team, were their attention to this thread, will they an answer for it?

I would like to store some extra information in the subject, because of the subject auto propagated in the cluster and between the layers eg. Bussiness Logic and the Domain (entities) and these informations needed for me everywhere.
We would like to develop a healtcare system and we always need to known about who is who recorded the data (an assistant), who is who diagnosed the patient (a doctor) and where happend it (a department). These information could be declared in the login process and these fixed until to logout and much more the intercept of their rights will be the real rights.
Thus if evry EJB call will destroy the subject and rebuild it by a background login mechanism our properetiary datas will be lost.

I put my full GFv3.1_M1 tests and their logs into this thread, please calling their attention to this thread again.

Thanks a lot, Attila.
[Message sent by forum member 'aszomor']

http://forums.java.net/jive/thread.jspa?messageID=472359