spring-projects/spring-security · warning

***** UI security is disabled. All unauthorized content…

Error message

***** UI security is disabled. All unauthorized content will be displayed *****

What it means

TagLibConfig static initializer warns when system property spring.security.securedUIDisable is set to true: the security taglibs will render all content (including blocks that would normally be hidden from unauthorized users), effectively disabling UI-level protection.

Solutions

  1. Remove -Dspring.security.securedUIDisable=true from JVM startup arguments and restart
  2. Never rely on taglib hiding as your only access control — enforce authorization server-side (authorizeHttpRequests)
  3. Verify the property value with a startup check if you must keep taglib security

Example fix

// before
JAVA_OPTS="... -Dspring.security.securedUIDisable=true"
// after
JAVA_OPTS="... " # property removed, UI security active
Defensive patterns

Strategy: validation

Validate before calling

if (Boolean.parseBoolean(System.getProperty("spring.security.securedUIDisable", "false"))) {
    logger.warn("securedUIDisable=true detected at startup — taglib UI security is OFF");
}

Prevention

When it happens

Trigger: JVM started with -Dspring.security.securedUIDisable=true; the static TagLibConfig initializer reads this property at first taglib use.

Common situations: Leftover debug/test JVM flags in production startup scripts; copying test server args into deployment; framework versions that default this property on.

Understand the failure class

Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/f89940e1c62e24e4. Report an issue: GitHub.

Appendix: source

Thrown at taglibs/src/main/java/org/springframework/security/taglibs/TagLibConfig.java:48

public final class TagLibConfig {

	static Log logger = LogFactory.getLog("spring-security-taglibs");

	static final boolean DISABLE_UI_SECURITY;

	static final String SECURED_UI_PREFIX;

	static final String SECURED_UI_SUFFIX;

	static {
		String db = System.getProperty("spring.security.disableUISecurity");
		String prefix = System.getProperty("spring.security.securedUIPrefix");
		String suffix = System.getProperty("spring.security.securedUISuffix");
		SECURED_UI_PREFIX = (prefix != null) ? prefix : "<span class=\"securityHiddenUI\">";
		SECURED_UI_SUFFIX = (suffix != null) ? suffix : "</span>";
		DISABLE_UI_SECURITY = "true".equals(db);
		if (DISABLE_UI_SECURITY) {
			logger.warn("***** UI security is disabled. All unauthorized content will be displayed *****");
		}
	}

	private TagLibConfig() {
	}

	/**
	 * Returns EVAL_BODY_INCLUDE if the authorized flag is true or UI security has been
	 * disabled. Otherwise returns SKIP_BODY.
	 * @param authorized whether the user is authorized to see the content or not
	 */
	public static int evalOrSkip(boolean authorized) {
		return (authorized || DISABLE_UI_SECURITY) ? Tag.EVAL_BODY_INCLUDE : Tag.SKIP_BODY;
	}

	public static boolean isUiSecurityDisabled() {
		return DISABLE_UI_SECURITY;
	}

View on GitHub (pinned to 96852e8860)