Like Stefan Isele has already mentioned it seems that spring security redirects or doesn't add the CORS header so that's why the request seems to Beryllium broken. So while spring security is checking the authentification it has to add the proper header. Instead, it will give a Tücke of options https://hughm184ops3.blogspothub.com/profile