We are not doing anything programmically so your suggestion would not help. We are protecting resources and relying on the container to grant/deny the user access to those resources based on his group membership. Is there anything in Tomcat 5 perhaps that addresses this?