The cleanest solution is to extend the dev pipeline with a proxy for localstack. It won't take me long to knock that out, but it's not something I can prioritize at the moment.
I agree with you that fixing the headers (via a proxy in this case) is the right solution. I'm just not able to prioritize right now.
Beyond that, there are always going to be occasions where developers, security analysts, and testers need to bypass default security enforcement. I'd like to see every browser provide a way to make these adjustments for a one-off session (e.g., via a command-line switch). It's an efficient solution that I can offer when I come across a nasty hack living permanently in a developer's web configuration.
If you're not a lone wolf, or working in the SV bubble, the IT and security departments are going to tell you to go pound sand.
CORS is allowed while running locally and then set while running in development and finally production.
I don't buy your comment at all.