allowedOrigins property
Origins allowed to call the server, e.g. https://myapp.dev.
'*' allows any origin. Otherwise a matching request Origin is echoed
back, and requests from other origins get no CORS headers (so the browser
blocks them).
Implementation
final List<String> allowedOrigins;