The annswer of M. Deinum is correct: the behaviour is expected. See the documentation.
NOTE: Specifying a securityMatcher overrides this default.
WARNING: If no filter chain matches a particular request, the request is not protected by Spring Security.