For testing purposes, a separate branch of the TODO app without the use of aerogear-controller needs to be created.
An attempt was made in [1] but security subsystem is not correctly initialized with the end-result of having full access to all rest endpoints.
Steps to reproduce:
'mvn clean install'
'curl --verbose -H "Accept: application/json" -H "Content-type: application/json" -X GET http://localhost:8080/todo-server/tags
The results are still retrieved
[1] https://github.com/abstractj/TODO/tree/ag-sec