I was playing around spring security and trying to secure an restful application, but then ran into this rather absurd problem. All the action on my controllers are fine and the
You must pass on the request on to the chain and you don't in case (header != null && headerContainsprefix)