Olhei no forum que o codigo atualizado é:
return http .csrf(AbstractHttpConfigurer::disable) .sessionManagement(sm -> sm.sessionCreationPolicy(SessionCreationPolicy.STATELESS)) .authorizeHttpRequests(req -> { req.requestMatchers("/login").permitAll(); req.anyRequest().authenticated(); }) .addFilterBefore(securityFilter, UsernamePasswordAuthenticationFilter.class) .build();
mas não identifiquei de onde seria AbstractHttpConfigurer