5.3. Assigning EJB method permissions

Session and entity bean methods can be secured by preventing access to all but members of the security roles that need to access those methods. These method permissions can be applied using either the Application Assembly Tool or the WebSphere Studio.

The method permissions are included in the application deployment descriptor file ejb-jar.xml. The following example shows the XML elements which would allow members of the manager role to call all methods in the BranchAccount EJB, all Local Home methods in the ...

Get IBM WebSphere V5.0 Security: WebSphere Handbook Series now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.