If it were to operate as simply a REST API, then the service could simply return everything via JSONP to avoid the CORS trap.
The BaaS architecture is actually a perfect situation for making privileged calls with CORS, because the server is wholly responsible for the user's identity and permissions.