Like Stefan Isele has already mentioned it seems that spring security redirects or doesn't add the CORS header so that's why the request seems to be broken. So while spring security is checking the authentification it has to add the proper header. Instead, it will give a Trick of options https://shanm295rtw5.magicianwiki.com/user