EJB2 has this check. Not sure whether it is implemented for ejb3.
Things like:
setSessionContext should disallow calls on getEJBHome, getCallerPrincipal,
getMessageContext and such.
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4111060#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...