Also I don't see a test in the kernel project that is validating
that you can't use the xml deployment (or programmatic deployment)
to bypass the private field access.
e.g. See the AccessControlContextTestCase that validates
that somebody can't use the MC to get access the system properties if they
don't have the right to do so.
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4137044#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...