1. Web.xml: why so poor flexibility for url-patterns in security contraints ?

I'm using GlassFish 3.1 and wanted to use container authentication. When I started writing security constraint in the web.xml I had the feeling that url patterns have very little flexibility. Chapter 12.2 ...

2. JSP/URL Copy Security

3. URL for JSP (regarding security)