Thanks @Anil_Chennapragada for the respond. I already had done same you said , deny every thing and allowed only specific paths , even then it is allowing the jcr:content.-1.json selector.I have already tried the below one but no luck. /0003 { /type "deny" /selectors '([0-9-]+| jcr:content | -1)' /...