One more comment to clarify, I made no provision in my login module to obtain credentials,
ie callbackhandler or anything like that. It strictly relied on a valid SMSESSION cookie.
If it was available and valid it would succeed, otherwise it would fail.
View the original post :
http://www.jboss.org/index.html?module=bb&op=viewtopic&p=4210855#...
Reply to the post :
http://www.jboss.org/index.html?module=bb&op=posting&mode=reply&a...