# Run with --spring.profiles.active=hs256,csrfon to reproduce the failure in # docs/04-csrf-permitall-403.md: a permitAll() login endpoint answering 403. demo: csrf: enabled: true