Very interesting article, Bruce. I especially appreciated the quote about instance-based programmatic security in EJBs. We have an implementation of this for a J2EE project, but it's very specific to our application. Do you know of any more general solutions to this problem? Or is it one of the issues to be resolved in EJB 3.0?
I read up on the Spring framework, and it does not appear to address this problem. Did I miss something there?
TIA,
- Bill |