The reference guide should clearly specify the permissions to be assigned to the Hibernate Validator code base when running with a Java security manager. A sample policy file would be very helpful.
For the sake of completeness also the BV API JAR should be covered (it needs a read {{java.io.FilePermission}} in order to detect the providers).
|