It depends on your application, and how you want to authorize users to
access secured resources. Role-based security and CAS are two
different things. If a user doesn't have permissions to run code or
access a resource, then CAS doesn't come into play since the code
isn't going to load.


>The way I am looking at the CAS is that it can be used to provide access control. And I have the other option, Rolebased security, to provide the same. If I use the later, do I have to do anything with CAS also?