CORS should not be baked in into the framework, especially with defaults. Configuring CORS is a error-prone, complicated task, we should let users take 100% responsibility of setting it up themselves; and disabling CORS should simply mean "not using the CORS extension".
Acceptance criteria