There are seemingly two ways to allow Cross Origin domains...
My preferred way of doing it, because it locks access down to only the specified domains that I allow.
- Set Origin Environment
SetEnvIf Origin "http(s)?://(www\.)?(([a-z0-9-]+).domain1.org|([a-z0-9-]+).domain2.org|test.devserver.org)$" AccessControlAllowOrigin=$0
- Use that Environment variable to add the header dynamicially