If the URLs are actually made public on the webserver, the GSA will
think that they are public (not really sure why you would want to
block something that was actually public). You may be able to trick
the GSA into thinking that they are secure by adding a fake forms auth
rule and making sure the Make Public checkbox is not checked. The GSA
will then try to execute that bogus rule *before* it crawls and mark
the document as secure even if it is not. This will not work if you
use the Crawler Access settings since these patterns are not used
until after the GSA first tries to crawl them (needed for the initial
auth challenge).
Hope this helps.
Brian