I think that the ajax you are using is not going through the portal and therefore does not
have the same security.
Enabling tomcat sso should solve your issue.
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4140280#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...