I\'m using Spring Security 3.2 with CSRF. My configuration includes this:
<
I may not understand something... but cant you just remove default-target-url from your configuration?