Uploaded image for project: 'EJB 3.0'
  1. EJB 3.0
  2. EJBTHREE-1036

TimeOut method callback should bypass security as it has no security context

    XMLWordPrintable

Details

    • Task
    • Resolution: Unresolved
    • Major
    • None
    • None
    • None
    • None
    • Medium

    Description

      Spec 18.2.2:
      "Since the timeout callback method is an internal method of the bean class, it has no client security context. When getCallerPrincipal is called from within the timeout callback method, it returns the container's representation of the unauthenticated identity."

      Basically the ejbTimeout callback should have zero security checks (bypass auth, authorization, runas). This is in line with ejb2.

      Attachments

        Issue Links

          Activity

            People

              anil.saldhana Anil Saldanha (Inactive)
              anil.saldhana Anil Saldanha (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated: