![]() |
![]() |
||||
This elements lists all roles which can gain access to a resource protected in a <security-constraint>.
Roles are listed using the <role-name> subelement.
Each role used in an <auth-constraint> must also be listed in a <security-role> section, which lists all the roles used in the application.
Each role must also exist in the Security Realm itself (for example, a JDBC Authentication Realm).