i'm using a similar approach for openId integration.
the seam authenticate method looks up a status from the session that is only set by the
servlet that confirms openId authentication
an improvement of the seam security framework to handle single sign on like openId or
others seams very relevant.
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4122994#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...