The response from OPTIONS must also contain "Origin" inside Access-Control-Allow-Headers, for example:
Access-Control-Allow-Headers: Origin,Authorization,X-Requested-With,Accept,Accept-Encoding,X-Accept-Charset,X-Accept,Content-Type