When configuring Spring Security, you must allow anonymous access to the URL /login(either login.htmlif it is a non-vaadina form, or the path to the login interface if you want to use a separate login interface). You also need to restrict access to the actual user interface of the application. It is also necessary to allow anonymous access to static resources (i.e. /VAADIN/**).
SecurityConfig Bakery . (: )
, Vaadin Spring (.. no spring -boot).