https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS Must specify exact origin (no wildcards), and headers when allowing credentials Respond to preflight requests with a 204 no content