Instead of getting 401 (that is the standard code for wrong authentication hinein spring security) I get It's some sort of security policy that browsers are strictly applying for the safety of the users and that's why you are not facing it when you tried your API via Postman/Swagger or https://eddiet417tuu4.fare-blog.com/profile