Hi Remy,
An endpoint that secures POST only should still allow GET.
This is a very common use case in web servies since wsdl access is GET
and web service invocation is POST.
http://jira.jboss.org/jira/browse/JBCTS-542
cheers
-thomas
--
xxxxxxxxxxxxxxxxxxxxxxxxxxxx
Thomas Diesler
Web Service Lead
JBoss, a division of Red Hat
xxxxxxxxxxxxxxxxxxxxxxxxxxxx