The following are known issues for the Worklist Manager Service Engine:
The default Worklist Manager Console does not support Access Control Lists (ACL) security. This means that users can view and reassign tasks that are not assigned to them.
To work around this issue, you can customize the console to enforce ACL security.
For security and authentication purposes, the default Worklist Manager Console must be deployed on the same server that the Worklist Manager Service Engine is installed on.
To work around this issue, you can customize the console to have a user's identity explicitly resolved by the GlassFish security realm from another server. This requires customizing index.jsp in the sample WLM Console project using the methods in TaskListPage.