Details
-
Bug
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
1.5.1
-
None
-
None
Description
When call sessionContext.getCallerPrincipal in a @Asynchronous method, It return a guest principal.
Section 4.5.4 of JSR 318 ejb 3.1 spec final release says it should propagate caller security principal.
> 4.5.4 Security
> Caller security principal propagates with an asynchronous method invocation. Caller security principal
> propagation behaves exactly the same for asynchronous method invocations as it does for synchronous
> session bean invocations.