Here is a part from Spring Security petclinic example:
<http use-expressions="true">
<intercept-url pattern="/" access="permitAll"/>
<intercept-url pattern="/static/**" filters="none" />
<intercept-url pattern="/**" access="isAuthenticated()" />
<form-login />
<logout />
</http>
What is the difference between access="permitAll" and filters="none"?
Url: http://static.springsource.org/spring-security/site/petclinic-tutorial.html