Objects, you're right. I had to change the order of the security items for it take effect.
<http>
<intercept-url pattern='/dacsLogin.htm' filters='none'/>
<intercept-url pattern='/system/**' access='ROLE_SUPER' />
<intercept-url pattern='/admin/**' access='ROLE_ADMIN' />
<intercept-url pattern='/**' access='ROLE_BASIC' />
<form-login login-page='/dacsLogin.htm
</http>
The above seems to work perfectly.
Thanks for your pointer.
Jared
Main Topics
Browse All Topics





by: objectsPosted on 2009-03-28 at 15:59:44ID: 24010679
> <intercept-url pattern='/**' access='ROLE_BASIC' />
because you grant access to ROLE_BASIC for all pages