JSPs /admin/* BASIC ...
<security-constraint> <web-resource-collection> <web-resource-name>JSPs</web-resource-name> <url-pattern>/admin/*</url-pattern><!-- 拒絕直接訪問web文件夾下的所有頁面 --> </web-resource-collection> <auth-constraint/> </security-constraint> <login-config> <auth-method>BASIC</auth-method><!-- 驗證方式(BASIC/FORM) --> </login-config>