Is it valid, standard and best practice to place
publicly accessible pages be outside the WEB-INF folder such as
index.jsp, home.jsp, store.jsp, login.jsp, registration.jsp...
andsecured pages like
admin.jsp, reports.jsp, manageusers.jsp, manageproducts.jsp...
be inside the WEB-INF folder for the security reasons(cannot directly access via url) by creating controller servlets to access them
and for includes like
navigation.jsp, header.jsp, footer.jsp, sitemap.jsp...
be in specially protected directory for not to be directly access from url ??