This is certainly possible. I have additional steps going on in my login() method, so our
environments and needs differ. You may also have additional login modules configured.
Again, all I can tell you at this point is that I tested adding the UserPrincipal in both
my valve, and then in a separate round of testing, within my custom JAAS module. I ran
several tests in both contexts where I removed, and then added back, the UserPrincipal.
This object definitely has an effect on the dashboard. With it, no 403. Without it, I got
the 403 consistently.
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4091137#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...