If IdentityManager.verify(Account) returns null, shouldn't
CachedAuthenticatedSessionMechanism return NOT_ATTEMPTED instead of
aborting and returning 403/NOT_AUTHENTICATED? I was expecting that
returning null would start the auth process again.
--
Bill Burke
JBoss, a division of Red Hat
http://bill.burkecentral.com