Aug 25, 2018

[HDGEM] JAX-RS specification does not define dedicated security related features

Except for a few API constructs (which act as high level abstractions).

For server side JAX-RS users (Java EE) it's critical to understand that the JAX-RS framework leverages the security capabilities of the container itself.

To be specific, since JAX-RS is built on top the Servlet API, it has access to all the security features
defined by the specification.

