I wonder what is the best approach to the web based security. Could you please give me some advise. Is JAAS overkill? Is HttpSession secure enough?