protected boolean abortTokenResponse() {
   if (facade.getSecurityContext() == null) {
     log.debugv("Not logged in, sending back 401: {0}", facade.getRequest().getURI());
     facade.getResponse().setStatus(401);
     facade.getResponse().end();
     return true;
   }
   if (!deployment.isExposeToken()) {
     facade.getResponse().setStatus(200);
     facade.getResponse().end();
     return true;
   }
   // Don't allow a CORS request if we're not validating CORS requests.
   if (!deployment.isCors() && facade.getRequest().getHeader(CorsHeaders.ORIGIN) != null) {
     facade.getResponse().setStatus(200);
     facade.getResponse().end();
     return true;
   }
   return false;
 }