A quick mockup test shows this is at least feasible. Throughout the entire verification
process the URLStreamHandler.connect() method is never called so it doesn't have to be
a "real" handler in order for security checks to work.
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4181092#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...