spring-projects/spring-security · warning
***** UI security is disabled. All unauthorized content…
Error message
***** UI security is disabled. All unauthorized content will be displayed *****
What it means
TagLibConfig static initializer warns when system property spring.security.securedUIDisable is set to true: the security taglibs will render all content (including blocks that would normally be hidden from unauthorized users), effectively disabling UI-level protection.
Solutions
- Remove -Dspring.security.securedUIDisable=true from JVM startup arguments and restart
- Never rely on taglib hiding as your only access control — enforce authorization server-side (authorizeHttpRequests)
- Verify the property value with a startup check if you must keep taglib security
Example fix
// before JAVA_OPTS="... -Dspring.security.securedUIDisable=true" // after JAVA_OPTS="... " # property removed, UI security active
Defensive patterns
Strategy: validation
Validate before calling
if (Boolean.parseBoolean(System.getProperty("spring.security.securedUIDisable", "false"))) {
logger.warn("securedUIDisable=true detected at startup — taglib UI security is OFF");
} Prevention
- Audit JVM startup flags in deployment scripts for spring.security.securedUIDisable
- Enforce real authorization server-side (authorizeHttpRequests) — taglib hiding is cosmetic only
- Fail fast in staging if this property is set in production-like environments
When it happens
Trigger: JVM started with -Dspring.security.securedUIDisable=true; the static TagLibConfig initializer reads this property at first taglib use.
Common situations: Leftover debug/test JVM flags in production startup scripts; copying test server args into deployment; framework versions that default this property on.
Understand the failure class
Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- No visible WebInvocationPrivilegeEvaluator instance could…
- No visible WebSecurityExpressionHandler instance could be…
- Your keytab is in the classpath. This file needs special…
- A filter chain that matches any request
- An error occurred while attempting to decode the Jwt…
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/f89940e1c62e24e4.
Report an issue: GitHub.
Appendix: source
Thrown at taglibs/src/main/java/org/springframework/security/taglibs/TagLibConfig.java:48
public final class TagLibConfig {
static Log logger = LogFactory.getLog("spring-security-taglibs");
static final boolean DISABLE_UI_SECURITY;
static final String SECURED_UI_PREFIX;
static final String SECURED_UI_SUFFIX;
static {
String db = System.getProperty("spring.security.disableUISecurity");
String prefix = System.getProperty("spring.security.securedUIPrefix");
String suffix = System.getProperty("spring.security.securedUISuffix");
SECURED_UI_PREFIX = (prefix != null) ? prefix : "<span class=\"securityHiddenUI\">";
SECURED_UI_SUFFIX = (suffix != null) ? suffix : "</span>";
DISABLE_UI_SECURITY = "true".equals(db);
if (DISABLE_UI_SECURITY) {
logger.warn("***** UI security is disabled. All unauthorized content will be displayed *****");
}
}
private TagLibConfig() {
}
/**
* Returns EVAL_BODY_INCLUDE if the authorized flag is true or UI security has been
* disabled. Otherwise returns SKIP_BODY.
* @param authorized whether the user is authorized to see the content or not
*/
public static int evalOrSkip(boolean authorized) {
return (authorized || DISABLE_UI_SECURITY) ? Tag.EVAL_BODY_INCLUDE : Tag.SKIP_BODY;
}
public static boolean isUiSecurityDisabled() {
return DISABLE_UI_SECURITY;
}View on GitHub (pinned to 96852e8860)