The Access-Control-Allow-Origin header will be set to the client's origin only if the client's origin exactly matches the value you provide.
Access-Control-Allow-Origin