, springsecurity ejb, : JAAS + springsecurity.
JAAS ejb , JMAS LoginModule, springsecurity.
EJB , jsr250 (RolesAllowed), spring .
In this way, I have achieved a clear separation between ejb and spring security, so my springsecurity protected business code is fully portable to any other kind of ApplicationServer, or it can even run as a standalone application.
source
share