4 Replies Latest reply on Mar 18, 2008 9:31 AM by joe_the_quick

    security-constraints not working at the page level (*-object

      hi there,

      If I add the Authenticated-role to a page (using Jboss Portal 2.6.2 GA), it seems to simply get ignored:

      <?xml version="1.0" encoding="UTF-8"?>





      The role is added to portlet.xml and can be verified using request.isUserInRole("Authenticated").
      If I add the same role to the portlet-instances.xml, then it works immediately:

      <?xml version="1.0" encoding="utf-8" standalone="yes"?>
      <!DOCTYPE deployments PUBLIC
      "-//JBoss Portal//DTD Portlet Instances 2.6//EN"



      Environment info:
      Jboss 4.0.5 GA
      Jboss Portal 2.6.2 GA
      JDK 1.5

      Could it be that the page-level security is no longer working with Jboss Portal 2.6.2 GA?

      I read in an earlier post, that the unchecked access using "read recursive" has to be disabled from the default-portal, but I believe that the role security should be way stronger than any default configuration.