users@servlet-spec.java.net

[servlet-spec users] Re: Standardizing authentication modules in Servlet (via JASPIC)?

From: Stuart Douglas <sdouglas_at_redhat.com>
Date: Sun, 2 Nov 2014 18:01:54 -0500 (EST)

> Of course compliant implementations would need to be tested with the
> TCK, that's a given. But in case of JASPIC I'm afraid it wouldn't win
> you much practically speaking. I'm really not sure what the JASPIC TCK
> exactly tests, but it just can't be much.
>

I think the test suite was expanded a bit for EE7, but it is still only about 40 tests. I know Wildfly's JASPIC implementation was broken for a long time, and it was not until Arjan contacted us about it that it got fixed.

In terms of user demand we have not really seen much, although it sounds like there have been lots of incompatibilities and problems with the existing implementations so perhaps this is not surprising. If this was more widely supported and there was greater compatibility between containers maybe demand would increase, but I would not want to put money on it.

Stuart

> Anyway, thanks a lot for your answers Mark. Really appreciate it!
>
> Kind regards,
> Arjan Tijms
>
>
> >
> > Mark
> >
>