I found it very confusing that SwarmStrategy.logoff(Object context) wants a
LoginContext, with JavaDoc saying "and must be the same (or equal) to the
logincontext used to log in.". That sounded as if the user had to enter his
password to logout, or that one should store the loginContext in the
session.

This part of the code of SWARM is still a mystery to me. Unfortunately, the
only person that knew what this code is supposed to do is no longer with us.
If you can figure out what it does, and how it can be made better, you are
more than welcome to send me some patches and I'll give a look at it.

I will.

Finally I believe there is a bug in SimpleRole.add(), at least in my
version it goes:

Sorry, that was Shiro code, I got confused.

Reply via email to