This issue was discovered while updating the TODO app to use aerogear-controller and aerogear-security-picketlink. The problem is that it should be enough that a user belongs to one of the roles, to be allowed access to the protected resource. This task should update the hasRoles method to return true the logged-in users has any of the roles passed in.
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira