Thus defeating the purpose of application-managed security to begin with. Now you have a
recorded credential (username/password) somewhere. Oh, BTW, you are assuming that the
account has the appropriate DB permissions to execute recovery right ;-)
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4009616#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...