A) The password was being sent in full to the server, over HTTPS?
B) The password was being sent in full to the server, over a plain text (unencrypted) channel?
It sounds like the CTO was claiming the former (A).
If you are running JS on the client anyway, then it seems reasonable to pass the client the salt, and ask only for the hash of the salted password.
But, if you say it's never OK to send the full (unhashed) password over HTTPS, then this implies it's not OK to have a fully server-side web app with password authentication. Because the only way to validate the password is for the client to send the whole password (unless you only ask for specific characters, but then password storage gets harder).