We use the PolicyContext api to get the active subject. In a stand alone environment, this is not valid. If we are unable to get the active subject via the policy context api, rather than throwing a RTE, we should log the error and move on to accept the active subject from the SecurityContext.
JBossAuthorizationManager has an expectation of SubjectPolicyContextHandler for getting Active Subject
-
Anil Saldanha (Inactive)
-
Anil Saldanha (Inactive)
- Votes:
-
0 Vote for this issue
- Watchers:
-
0 Start watching this issue
- Created:
- Updated:
- Resolved: