Same-origin requests don't need CORS restrictions. Users can optionally set ALLOWED_ORIGINS to lock it down.