Ignorar o Java Web Security permitir tudo
http.authorizeRequests().antMatchers("/login*").permitAll();
Scary Skylark
http.authorizeRequests().antMatchers("/login*").permitAll();