diff --git a/spring-boot-docs/src/main/asciidoc/spring-boot-features.adoc b/spring-boot-docs/src/main/asciidoc/spring-boot-features.adoc index 20f3ebc984..3e4af9143a 100644 --- a/spring-boot-docs/src/main/asciidoc/spring-boot-features.adoc +++ b/spring-boot-docs/src/main/asciidoc/spring-boot-features.adoc @@ -2316,7 +2316,11 @@ The basic features you get out of the box in a web application are: All of the above can be switched on and off or modified using external properties (`+security.*+`). To override the access rules without changing any other auto-configured features add a `@Bean` of type `WebSecurityConfigurerAdapter` with -`@Order(SecurityProperties.ACCESS_OVERRIDE_ORDER)`. +`@Order(SecurityProperties.ACCESS_OVERRIDE_ORDER)` and configure it to meet your needs. + +NOTE: By default, a `WebSecurityConfigurerAdapter` will match any path. If you don't want +to completely override Spring Boot's auto-configured access rules, your adapter must +explicitly configure the paths that you do want to override.