In web.xml, you can add this security-constraints.

    <display-name>JSP Protection</display-name>
      Nobody should be in this role so JSP files are protected from direct access.

Sometime, some servlet or jsp may be not protected.

    <display-name>JSP Protection</display-name>
    <display-name>NOT JSP Protection</display-name>

      Nobody should be in this role so JSP files are protected from direct access.


'web' 카테고리의 다른 글

apache httpd와 light httpd의 성능 비교  (0) 2009.07.13
Restarting Tomcat, log4j error  (0) 2009.07.09
아파치 에러 해결 No space left on device  (0) 2009.02.17
Content-disposition 속성  (0) 2009.02.13
dbcp가 자주 끊길 때..  (0) 2009.02.11
Posted by '김용환'