Karl Palsson (Migrated from SEC-1183) said:
Exactly the same as the forum thread, only I never saw another answer or a ticket filed from that user.
or, possibly, would it be enough for an alias around IS_AUTHENTICATED_FULLY and IS_AUTHENTICATED_REMEMBERME ?
Luke Taylor said:
The defaultRole property of the DefaultLdapAuthoritiesPopulator is a bit of an anachronism, so I don't want to add it to the LDAP namespace. Ideally we should allow any providers which are dealing with authorities to have an Attributes2GrantedAuthoritiesMapper instance which can be used to provide full control over the authority values. A defaultRole property could also be added to the SimpleAttributes2GrantedAuthoritiesMapper.