I record the information when i read the security of ws
1. authoriztion roles could detemine the level of access to system resource
2. privileged actions accompany a role.
3. the change is minor.
4. Tomcat provides container-managed security in three steps
5. the newly minted ['mintid] something -- 刚刚完成的事情
6. the low-level processing best left to the handler.
7.The example likewise suggests how complicated the intermix of application code and security code could become in a real-world service. Furthermore, the approch does not well.