Like Stefan Isele has already mentioned it seems that spring security redirects or doesn't add the CORS header so that's why the request seems to be broken. So while spring security is checking the authentification it has to add the proper header. They also have solutions for enterprise level issues, https://demosthenesj174mor3.blogginaway.com/profile