How do I protect JSF 2.0 facelets against direct access?
问题 I have found one idea here, putting files under /WEB-INF is a way to block direct access: With Facelets, one can also put XHTML files under the /WEB-INF, if they are templates or included files (same restrictions as with JSP essentially). The page also presents a solution based on Java EE security, which allows direct XHTML access only to members of a specific user group. <security-constraint> <display-name>Restrict XHTML Documents</display-name> <web-resource-collection> <web-resource-name