Greetings,

I would like to ask for some assistance. In general, we use Shiro for
authentication and authorisation successfully -- against AD realms.

However, we have a problem at one side only:

1) User can authenticate successfully with username (e. g. "andreas")
and e-mail (e. g. "[email protected]")
2) However, the same user can authorise only via e-mail (e. g.
"[email protected]") -- but not via username

This is extremely confusing for the end-users and a maintenance
nightmare because:

a) when the user logs-on successfully he also will expect to have the
assigned roles
b) the AD administrators only confirm, that user is active and has
roles

So, what can be done about this please?

Best regards
Andreas

Reply via email to