Facing Issue "Implementation of spring security with JWT authentication along with hilla's security"

I tried the implement the spring security along with Hilla security configuration, then hilla security is disabled. I am not able to login into the application.
Please, anyone have solution to implement both securities side by side and then user should be able to login into the application.

SpringSecurity configuration

Check GitHub - TatuLund/hilla-v2-demo: Hilla/React demo application using Hilla v2.2+ features like useForm to bind forms data and dataprovider with Grid to perform backend sorting and filtering. It has Spring Security config using JWT auhentication (Spring Boot 3.1) and use the latest Hilla 2.3 auth helpers with React. There some demos there how to restrict views, and action based on role on client and server.

Below is the security configuration extending Vaadin web security.

————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————
@EnableWebSecurity(debug = true)
@Configuration
@Slf4j
public class SecurityConfiguration extends VaadinWebSecurity {

@Value(“${com.test.secret}")
private String authSecret;
@Value("${login.expiryTime}")
private Long expiryTime;

@Bean
public PasswordEncoder passwordEncoder() {
    return new BCryptPasswordEncoder();
}

@Order(1)
@Override
protected void configure(HttpSecurity http) throws Exception {
    http.authorizeHttpRequests(
            authorize -> authorize.requestMatchers(new AntPathRequestMatcher("/images/*.png")).permitAll()
                    .requestMatchers(new AntPathRequestMatcher("/api/generateToken")).permitAll()
                    .requestMatchers(new AntPathRequestMatcher("/api/sample")).permitAll()
    .requestMatchers(new AntPathRequestMatcher(“/test/ping”)).permitAll()
    )
    .csrf((csrf) -> csrf.ignoringRequestMatchers(new AntPathRequestMatcher("/api/**/*")));

    super.configure(http);

    http.sessionManagement(customizer -> customizer.sessionCreationPolicy(SessionCreationPolicy.STATELESS));
    setLoginView(http, "/login");
    setStatelessAuthentication(http, new SecretKeySpec(Base64.getDecoder().decode(authSecret), JwsAlgorithms.HS256),”com.test”);
}

}
————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————————

Using @endpoint we defined api. As per configuration… “/login” api is granted without any security, and permitting other urls.

Now my requirement is to access few apis without vaadin and only JWT authentication.

Now my requirement is to access few apis without vaadin and only JWT authentication.