Can you not use a different application policy for your own logincontext.login() than the
one specified for your web application?
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=3996674#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...