19
What security framework do you use in your Java projects?
I used Spring Security and Apache Shiro and they both look immature.
Spring Security flaws:
- no native support for permissions;
- no ability to use explicitly in Java code (sometimes it's necessary);
- too much focused on classic (non AJAX) web applications.
Apache Shiro flaws:
- bugs in final release (like the problem with Spring integration);
- no support for OpenID and some other widely used technologies;
- performance issues reported.
There is also lack of documentation for both of them.
Maybe most of the real projects develop their own security frameworks?