try {
User user = securityManager
.getUserByLoginName(SecurityContextHolder.getContext()
.getAuthentication().getName());
Project project = requestManager.getProjectById(projectId);
if (!project.userCanRead(user)) {
throw new SecurityException("Permission denied.");
}
//return new ModelAndView("/pages/listRequests.jsp", "requests", requestManager.listAllRequests(user, project));
return null;
} catch (IOException ex) {