Mark, On 27/05/2021 18:19, Mark Thomas wrote:
I will note that it isn't uncommon to have to log out and back in again to pick up newly allocated groups/roles in other environments.
Yes, you are right. Didn't see it that way so far. We're talking about live updates for a session during its lifetime, which we can surely drop. Only few other Realms will support this (if any).
If we go the removal route then I'd treat that as a separate PR / bugzilla issue so any discussion remains focussed on the relevant issue.
The removal route seems simple. Both the UserDatabasePrincipal and the hasRole()-overwrite can be removed. That should do the trick.
I will provide a PR and file a corresponding issue in Bugzilla soon. Carsten --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org For additional commands, e-mail: users-h...@tomcat.apache.org