As a side goal, we could try and preserve the default behaviour in Spring Security (i.e. respect the `X-Requested-With` header).