Turns out CORS defaults to strict if no headers are sent at all, so this permissive default makes more sense.