The PolicyContext would just be a copy even if it was not read-only. One way would be to
simply add the roles to the invocation and update the authorization interceptor logic to
look there in addition to the RealmMapping.doesUserHaveRole call. Not having the roles
assigned to the Subject is the direction we are heading anyway.
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4020885#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...