{"record":{"id":"f89940e1c62e24e4","repo":"spring-projects/spring-security","slug":"ui-security-is-disabled-all-unauthorized-co","errorCode":null,"errorMessage":"***** UI security is disabled. All unauthorized content will be displayed *****","messagePattern":"\\*\\*\\*\\*\\* UI security is disabled\\. All unauthorized content will be displayed \\*\\*\\*\\*\\*","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"taglibs/src/main/java/org/springframework/security/taglibs/TagLibConfig.java","lineNumber":48,"sourceCode":"public final class TagLibConfig {\n\n\tstatic Log logger = LogFactory.getLog(\"spring-security-taglibs\");\n\n\tstatic final boolean DISABLE_UI_SECURITY;\n\n\tstatic final String SECURED_UI_PREFIX;\n\n\tstatic final String SECURED_UI_SUFFIX;\n\n\tstatic {\n\t\tString db = System.getProperty(\"spring.security.disableUISecurity\");\n\t\tString prefix = System.getProperty(\"spring.security.securedUIPrefix\");\n\t\tString suffix = System.getProperty(\"spring.security.securedUISuffix\");\n\t\tSECURED_UI_PREFIX = (prefix != null) ? prefix : \"<span class=\\\"securityHiddenUI\\\">\";\n\t\tSECURED_UI_SUFFIX = (suffix != null) ? suffix : \"</span>\";\n\t\tDISABLE_UI_SECURITY = \"true\".equals(db);\n\t\tif (DISABLE_UI_SECURITY) {\n\t\t\tlogger.warn(\"***** UI security is disabled. All unauthorized content will be displayed *****\");\n\t\t}\n\t}\n\n\tprivate TagLibConfig() {\n\t}\n\n\t/**\n\t * Returns EVAL_BODY_INCLUDE if the authorized flag is true or UI security has been\n\t * disabled. Otherwise returns SKIP_BODY.\n\t * @param authorized whether the user is authorized to see the content or not\n\t */\n\tpublic static int evalOrSkip(boolean authorized) {\n\t\treturn (authorized || DISABLE_UI_SECURITY) ? Tag.EVAL_BODY_INCLUDE : Tag.SKIP_BODY;\n\t}\n\n\tpublic static boolean isUiSecurityDisabled() {\n\t\treturn DISABLE_UI_SECURITY;\n\t}","sourceCodeStart":30,"sourceCodeEnd":66,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/taglibs/src/main/java/org/springframework/security/taglibs/TagLibConfig.java#L30-L66","documentation":"TagLibConfig static initializer warns when system property spring.security.securedUIDisable is set to true: the security taglibs will render all content (including blocks that would normally be hidden from unauthorized users), effectively disabling UI-level protection.","triggerScenarios":"JVM started with -Dspring.security.securedUIDisable=true; the static TagLibConfig initializer reads this property at first taglib use.","commonSituations":"Leftover debug/test JVM flags in production startup scripts; copying test server args into deployment; framework versions that default this property on.","solutions":["Remove -Dspring.security.securedUIDisable=true from JVM startup arguments and restart","Never rely on taglib hiding as your only access control — enforce authorization server-side (authorizeHttpRequests)","Verify the property value with a startup check if you must keep taglib security"],"exampleFix":"// before\nJAVA_OPTS=\"... -Dspring.security.securedUIDisable=true\"\n// after\nJAVA_OPTS=\"... \" # property removed, UI security active","handlingStrategy":"validation","validationCode":"if (Boolean.parseBoolean(System.getProperty(\"spring.security.securedUIDisable\", \"false\"))) {\n    logger.warn(\"securedUIDisable=true detected at startup — taglib UI security is OFF\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Audit JVM startup flags in deployment scripts for spring.security.securedUIDisable","Enforce real authorization server-side (authorizeHttpRequests) — taglib hiding is cosmetic only","Fail fast in staging if this property is set in production-like environments"],"tags":["taglibs","security","configuration","jsp"],"backgroundTag":"invalid-config-value","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}