I'm not the person you asked but I have my frontend hosted separately from the Heroku backend. CORS was a bit of a pain at first, mostly because I had never had to deal with it before, but after initial setup I never think about it.
We use Django REST and an angular frontend. Django is hosted on heroku, and angular is hosted on netlify. Netlify makes it super easy to proxy API requests from the front-end to our API backend.