Both the context data(such as roles) and authorization manager should be a function of the
security domain.
We need to workout the trust usecase workflows to define the spi. I don't think its
best embeded in the authentication call, but I"m not sure. How would 196 deal with a
saml identity assertion?
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=3968418#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...