Great document. When Java EE developers will have these possibilities, a
lot of use cases will be covered.
Maybe I would like to propose a small addition;
*4.6 API for Authorization Interceptors*
The use of "voters" to perform authorization. Something like the DeltaSpike
AccessDecissionVoter. (1)
This as the class based alternative for using EL.