* With the new cookie-based client sessions, CORS needs to be modified from allow-all to a specified domain/value