DB Login module approach is the common practice, but based on EAP documentation[1] it would require to setup also a DB at Openshift and populate it. I'm not sure if it worths all these effort to demonstrate deltaspike-authorization. I think we should try Emil Cervenan's instruction that is closest to Quickstarts intructions.
[1] https://access.redhat.com/documentation/en-US/JBoss_Enterprise_Application_Platform/6.3/html/Security_Guide/chap-Login_Modules.html#DatabaseServerLoginModule
|