The askdev origin pattern was missing a slash (https:/* instead of https://*), so requests from *.askdev.grundclock.com never matched the CORS allowlist and got no Access-Control-Allow-Origin header.
The askdev origin pattern was missing a slash (https:/* instead of https://*), so requests from *.askdev.grundclock.com never matched the CORS allowlist and got no Access-Control-Allow-Origin header.