I have https://domain1.com (domain1) and https://domain2.com (domain2).
Domain2 serves a page containing javascript with this header:
"Access-Control-
Do you have allow methods set?
Try adding this to your header:
Access-Control-Allow-Methods: POST, GET, OPTIONS