Thanks for pointing this out. The filter order is in the application.properties file. However, I forgot to mention in the tutorial. Setting security.oauth2.resource.filter-order to 3 is required because the @EnableResourceServer annotation creates a
WebSecurityConfigurerAdapter with a hard-coded
Order (of 3) by default. The orders need to be aligned.