The problem was that I had not specified any method-permission roles for the call, nor had i said the method was unchecked.
Adding a method permission solved the problem. Hurrah. Now i still have the issue that with the next invocation ( like resubmitting the page for example) the principal is kept, but the roles are reset to null, and thus get a permission error. It seems like the authentication cache is not caching the roles? Thanks for any help! View the original post : http://www.jboss.org/index.html?module=bb&op=viewtopic&p=3854643#3854643 Reply to the post : http://www.jboss.org/index.html?module=bb&op=posting&mode=reply&p=3854643 ------------------------------------------------------- This SF.Net email is sponsored by: Sybase ASE Linux Express Edition - download now for FREE LinuxWorld Reader's Choice Award Winner for best database on Linux. http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click _______________________________________________ JBoss-user mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/jboss-user