Carsten Ziegeler wrote: > As both, auth-fw and session-fw are really out dated and as cowarp is a > better implementation of the auth-fw, I propose to: > a) deprecate auth-fw and session-fw in 2.1.x > b) remove auth-fw and session-fw in 2.2 > c) add cowarp as an own block to 2.2 >
+0. I never used auth-fw nor cowarp and use a homegrown solution that provides in-application authentication and authorization while still allowing the use of the regular request.isUserInRole() and request.getUserPrincipal() using a request filter. Sylvain -- Sylvain Wallez - http://bluxte.net