SECURITY: Fix CORS origin matching in the API