I have csrf protection in spring framework. So in each request I send csrf token in header from ajax call, which is perfectly working.
&
If you don't want to configure environment variables etc. here is the quickest solution
https://stackoverflow.com/a/49249850/3705478