Back to bug 1038397

Who When What Removed Added
David Jorm 2013-12-05 06:02:05 UTC Assignee rdickens twells
Tom WELLS 2013-12-06 00:40:49 UTC Status NEW ON_QA
Target Milestone --- GA
David Jorm 2013-12-06 00:41:41 UTC Status ON_QA VERIFIED
David Jorm 2013-12-06 00:42:26 UTC Status VERIFIED CLOSED
Resolution --- CURRENTRELEASE
Last Closed 2013-12-05 19:42:26 UTC
Scott Mumford 2014-07-16 23:58:35 UTC Status CLOSED MODIFIED
CC smumford
Resolution CURRENTRELEASE ---
Keywords Reopened
Scott Mumford 2014-07-17 00:03:00 UTC Target Release EAP 6.2.0 EAP 6.3.0
CC emuckenh
Component doc-Release_Notes Domain Management
Assignee twells smumford
Doc Text When JBoss EAP 6 was run with the Java Security Manager enabled, the Role-Based Access-Control system was effectively disabled because in this situation all authenticated users were treated as SuperUsers. The only way to use Role-Based Access-Control was without the Java Security Manager enabled.

This issue was fixed in this release by making all access to the current `AccessControlContext` happen outside of the privileged action. As a result, Role-Based Access-Control is now still effective when enabling the Java Security Manager.
Scott Mumford 2014-07-17 00:03:20 UTC Blocks 1036618, 1040480
Scott Mumford 2014-07-17 00:03:21 UTC CC lthon
John Skeoch 2014-10-21 00:07:43 UTC CC mjc
John Skeoch 2015-02-01 23:06:09 UTC CC emuckenh dandread
Scott Mumford 2015-02-23 01:36:41 UTC Status MODIFIED CLOSED
Resolution --- NOTABUG
Last Closed 2013-12-05 19:42:26 UTC 2015-02-22 20:36:41 UTC

Back to bug 1038397