Reimplement CORS properly, addressing Tim's concerns