I use Jersey for my REST API. I use JSP files for the views. I put my JSP view files in www/views/.... Now I’d like to forbid access to these views through simple HTTP request on their canonical URL.
What is the best way to forbid direct access to these JSPs from the client ?
Stick the JSPs under
/WEB-INFin the WAR.