What security framework do you use in your Java projects?

I used Spring Security and Apache Shiro and they both look immature.

Spring Security flaws:

  1. no native support for permissions;
  2. no ability to use explicitly in Java code (sometimes it's necessary);
  3. too much focused on classic (non AJAX) web applications.

Apache Shiro flaws:

  1. bugs in final release (like the problem with Spring integration);
  2. no support for OpenID and some other widely used technologies;
  3. performance issues reported.

There is also lack of documentation for both of them.

Maybe most of the real projects develop their own security frameworks?

Edit
Report