Cross origin requests are allowed (as long as they're simple). Reading the response is what's blocked.