My main issue with CORS is the latency doubling introduced by preflight requests. I wish there was a more secure escape hatch for that than including things like access tokens in the query parameters[0].
[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Ac...
That said, it would be cool if static hosting services like S3 offered CORS proxies for uses like this. I wonder if that's a thing.