Hello, how does one use css and image files that are located under
webapp's root in separate subdirectories on login page before user have
logged in?

I'm thinking of something like this:
     <security-constraint url-pattern='/css/*' role-name='*'/>
     <security-constraint url-pattern='/img/*' role-name='*'/>

According to my knowledge, role * means every role. This makes it very
problematic, because an user that haven't logged in have no role (null) so
these clauses wouldn't match.

Of course one could copy these files to another location, but I'd rather
avoid creating duplicates of these files if possible - even it's easy to
automate the copy process with an ant script or so.


