It should look like so:
Notice the CORS header (access-control-allow-origin: *) in the “Response Headers” section.
access-control-allow-origin: *