SecurityContextHolder
For a detailed background on what this filter is designed to process, refer to RFC 1945, Section 11.1.
SecurityEnforcementFilter
Once a user agent is authenticated using BASIC authentication, logout requires that the browser be closed or an unauthorized (401) header be sent.