in app/src/main/java/com/amazon/aws/partners/saasfactory/pgrls/configuration/SecurityConfiguration.java [50:62]
public void configure(HttpSecurity http) throws Exception {
http.authorizeRequests()
.antMatchers("/", "/health", "/admin/**").permitAll() // no auth
.antMatchers("/tenant/**").authenticated() // tenant user management is authenticated
.and() // custom login form
.formLogin()
.loginPage("/login")
.permitAll() // anyone can access login
.and() // custom logout redirect
.logout()
.logoutSuccessHandler(logoutSuccessHandler())
.permitAll(); // anyone can access logout
}