We should add support for @Transient SecurityContext in HttpSessionSecurityContextRepository and then provide a SecurityContext that is annotated with @Transient