CORS is there for security and is enforced at the server, so I am afraid that what you are doing here will only work locally, i.e. cannot work when you run your web app in production.