have you tried ? .requestMatchers(POST, "/foo/*/baas/*").hasAnyRole(SUPER_HERO.name())
.requestMatchers(POST, "/foo/*/baas/*").hasAnyRole(SUPER_HERO.name())