Created attachment 31012 [details] Patch for Tomcat6 The attribute "allRolesMode" is not listed in the attributes for the CombinedRealm or LockOutRealm. I have been bitten by it as I thought it was then sufficient to put it in each of the nested Realms. It appears that the check for HasResourcePermission is done on the context.getRealm() which is not passed in the nested Realms in the case of CombinedRealm. I think just adding it to the documentation should be sufficient. I only have a working copy of Tomcat 6 handy, so the patch is done to that version.
Thanks for the patch. It has been applied to trunk, 7.0.x and 6.0.x and will be included in 8.0.0-RC6, 7.0.48 and 6.0.38 onwards.