I have a same domain, one of them is domain without prefix www. For example,
First domain works
This happens because you have specified both:
This configuration is not supported. See the doc:
Specifying AllowAnyOrigin and AllowCredentials is an insecure configuration and can result in cross-site request forgery. The CORS service returns an invalid CORS response when an app is configured with both methods.
You should remove the call to AllowAnyOrigin method