@Configuration @EnableWebSecurity public class SpringSecurityConfigurationBasicAuth extends WebSecurityConfigurerAdapter{ @Override protected void configure(HttpSecurity http) throws Exception { http .csrf().disable() .authorizeRequests() .antMatchers(HttpMethod.OPTIONS,"/**").permitAll() .anyRequest().authenticated() .and() //.formLogin().and() .httpBasic(); } }