Yesterday, our web application did a great job with WildFly 9. Since this morning, I only get βForbiddenβ in my web browser. We do not use JAAS. It also makes no difference if I set the following false to standalone.xml :
... <subsystem xmlns="urn:jboss:domain:ejb3:3.0"> ... <default-missing-method-permissions-deny-access value="true"/> ... </subsystem> ...
What could be the reason WildFly only shows the Forbidden page?
EDIT
If I set the log level for the org.jboss.security package to TRACE , I get the following message in the log file when the page is called:
2016-01-27 12:58:15,354 TRACE [org.jboss.security] (default task-5) PBOX00354: Setting security roles ThreadLocal: null
Not sure what that means ...
source share