<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#ffffff" text="#000000">
    On 3/4/11 5:12 PM, Balz Schreier wrote:
    <blockquote
      cite="mid:AANLkTikUrhz2i4U_ffKpjwpBRdRu0nksjyBr8nEMmOOW@mail.gmail.com"
      type="cite">please forget my mail below. sorry.
      <div><br>
      </div>
      <div>i see that getEnvironment().getIdentity() returns that
        "world" user object in case the user is not logged in.</div>
    </blockquote>
    <br>
    Maybe we can enhance the documentation and/or javadoc to make this
    clearer, e.g.<br>
    <br>
    <a class="moz-txt-link-freetext" href="http://www.yanel.org/en/documentation/security/overview.html">http://www.yanel.org/en/documentation/security/overview.html</a><br>
    <br>
    WDYT?<br>
    <br>
    Thanks<br>
    <br>
    Michael<br>
    <blockquote
      cite="mid:AANLkTikUrhz2i4U_ffKpjwpBRdRu0nksjyBr8nEMmOOW@mail.gmail.com"
      type="cite">
      <div><br>
      </div>
      <div>thanks.<br>
        <br>
        <div class="gmail_quote">
          On Fri, Mar 4, 2011 at 5:09 PM, Balz Schreier <span dir="ltr"><<a
              moz-do-not-send="true"
              href="mailto:balz.schreier@gmail.com">balz.schreier@gmail.com</a>></span>
          wrote:<br>
          <blockquote class="gmail_quote" style="margin: 0pt 0pt 0pt
            0.8ex; border-left: 1px solid rgb(204, 204, 204);
            padding-left: 1ex;">
            hi,
            <div><br>
            </div>
            <div>i use policies that authorize public users for certain
              usecases, so I use this in the usecase definition:</div>
            <div><br>
            </div>
            <div>
              <p><world permission="true"/></p>
              <p><br>
              </p>
              <p>How can I authorize a user request where the user is
                unknown?</p>
              <p><br>
              </p>
              <p>I use:</p>
              <p>
              </p>
              <p>realm.getPolicyManager().authorize(policyPath,
                identity, usecase);</p>
              <p><br>
              </p>
              <p>but identity is of course NULL for not logged in users.</p>
              <p>How can I run the authorization check for not logged in
                users?</p>
              <p><br>
              </p>
              <p>Thanks</p>
              <p>Cheers</p>
              <p>Balz</p>
            </div>
          </blockquote>
        </div>
        <br>
      </div>
    </blockquote>
    <br>
  </body>
</html>