Adds regression coverage for the custom accessDeniedHandler in SecurityConfig: a POST without X-XSRF-TOKEN returns 403 with error code CSRF_TOKEN_MISSING, not a generic Spring 403. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Adds regression coverage for the custom accessDeniedHandler in SecurityConfig: a POST without X-XSRF-TOKEN returns 403 with error code CSRF_TOKEN_MISSING, not a generic Spring 403. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>