Thomas Champagne (Migrated from SEC-1049) said:
The current SidRetrievalStrategyImpl don’t use the roleHierarchy to extract the authorities. So, when the AbstractAclProvider reads acls, only final roles are retrieved, not the whole tree of GrantedAuthoritySid.
I created a patch in the current trunk (2.5 SNAPSHOT). It is the same as RoleHierarchyVoter class.
Luke Taylor said:
Thanks Thomas. I've added the option of injecting a RoleHierarchy instance into the SidRetrievalStrategyImpl class.