- Changed `server.forward-headers-strategy` to `native` in `application.properties`. - Added exclusion for `/login/oauth2/code/**` in CSRF configuration.