所以下面的配置在服务端比较常见:
cres.getHeaders().add("Access-Control-Allow-Origin", "*");
cres.getHeaders...().add("Access-Control-Allow-Headers", "origin, content-type, accept");
cres.getHeaders().add...("Access-Control-Allow-Credentials", "true");
cres.getHeaders().add("Access-Control-Allow-Methods...", "GET, POST, PUT, DELETE, OPTIONS, HEAD");
cres.getHeaders().add("Access-Control-Max-Age",