There is a potential contribution from the community on setting the code source URL to the embedded jars of an ear/sar such that appropriate permissions may be assigned.
This contribution is making changes in the Unified Classloader. Hence it will work only in JBAS4.x and not in 5.x
AFAIR, we have been only dealing with the top level code source URLs to assign the permissions and have not really dealt with the internal embedded jars.
So this is definitely an area that we need to look at. I will discuss this at the next AS call and get back.