geronimo-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "David Jencks (JIRA)" <>
Subject [jira] Updated: (GERONIMO-2313) Subject not propagated correctly between web app and ejb
Date Thu, 10 Aug 2006 23:56:14 GMT
     [ ]

David Jencks updated GERONIMO-2313:

    Attachment: ejbrefsec.src.jar

Sample app to demonstrate the problem, together with m2 project source.

Deploy the ear.


localhost:8080/manifestcp/servlet in your browser

Look on the server console: it will tell you the result of isCallerInRole for each ejb access.
false means isCallerInRole is not working properly.

> Subject not propagated correctly between web app and ejb
> --------------------------------------------------------
>                 Key: GERONIMO-2313
>                 URL:
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>    Affects Versions: 1.1, 1.1.1, 1.1.x
>            Reporter: David Jencks
>         Assigned To: David Jencks
>             Fix For: 1.2
>         Attachments: ejbrefsec-ear-1.0-SNAPSHOT.ear, ejbrefsec.src.jar
> With a web app with security, that calls an ejb, isCallerInRole in the ejb always returns
> this is caused by the web app not setting nextCaller and the ejb interceptors shifting
nextCaller to currentCaller, so when the isCallerInRole is tested there is a null subject....
so it returns false.

This message is automatically generated by JIRA.
If you think it was sent incorrectly contact one of the administrators:
For more information on JIRA, see:


View raw message