I\'ve read many answers of preflight and CORS so please do not post links referencing what I should read. Many of the answers are from a server-perspective, but I am the cli
This post is old, but answering for anybody else who comes across it.
There is nothing wrong with your authorization header. The problem you are facing is CORS related.
You don't set the Origin header yourself. The browser does that for you. If your origin is null then I suspect this is because you are running your code from file:/// instead of http://.