Cross-Origin-Resource-Sharing policy
allow credential or not
allowed HTTP headers
allowed HTTP methods
allowed origins
expose HTTP headers
max time client can cache the result