I have developed a Spring Boot 2.2 web server/api that serves a website made in Angular 8. For that reason I enabled CSRF protection with the following configuration: