I am attempting to configure cache-control response header to a custom value via my Spring Security configuration XML.  Unfortunately, it seems like I'm only able to disable the cache-control header from the XML configuration as per the documentation:
<http>
    <headers defaults-disable="true">
        <cache-control />
    </headers>
</http>
Being this seems to be the case, I attempted to create a custom WebSecurityConfigurerAdapter as so:
@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        System.out.println("******* SETTING CUSTOM CACHE-CONTROL....");
        StaticHeadersWriter writer = new StaticHeadersWriter("Cache-Control", "2592000");
        RequestMatcher resourcesMatcher = new AntPathRequestMatcher("/**/*");
        HeaderWriter resourcesHeaderWriter = new DelegatingRequestMatcherHeaderWriter(resourcesMatcher, writer);
        http.headers().cacheControl().disable().addHeaderWriter(resourcesHeaderWriter);
        http.headers().disable();
    }
}
Unfortunately, even though the class is in fact initially called, it seems like the configuration is actually overwritten by the XML, as the cache-control response header still appears to be set to the defaults:
Any thoughts on how I can specify something similar with the XML file itself, preferably able to match a specific pattern (ex. *.js)?
Thanks!
