We should send a static message, e.g. "Access Denied" from HttpStatusServerAccessDeniedHandler instead of the exception message.

Comment From: kwondh5217

Hi @sjohnr ! I’ve submitted a PR to address this issue. Could you please take a look when you have time? Thanks!