It should be a large topic around CORS, and here just list some useful headers for solving CORS:

1. Access-Control-Allow-Origin (RESPONSE)

Indicates whether the response can be shared.

2. Access-Control-Allow-Methods (RESPONSE)

Specifies the methods allowed when accessing the resource in response to a preflight request.

