I've read about half of Pro Spring and for the most part, I think it's an excellent book. Nice job, Rob and Jan. As for security, it is not addressed at all in the book except for the following excerpt:
"Although we have not discussed application security in any detail in this book, it is still a very important topic. Traditionally, a
J2EE application utilizes the security features provided by the container to secure an application at both the
servlet and EJB levels..."
It would have been nice if they had covered some security techniques, but I understand their decision to leave it out. It's still a great book.
[ February 22, 2005: Message edited by: Andrew Patzer ]