* Don't make cors enabled on all (*) by default. * Handle related web.allowedOrigins options * Only the gateway api should be called by a browser so setup the cors handler only on it