I think the second recommendation is poorly worded. They both say you should avoid repeating the Origin header. "Countdown", I think, they imply the blind value of the Origin header in the Access-Control-Allow-Origin header without any intermediate checks (such as whitelisting). Also note that these are recommendations, not absolute rules, and should be interpreted through the lens of your needs. The more open and public the API, the more acceptable the * value.
source share