Client cannot sync - CORS error

For alternative approaches to mitigating the risk of clickjacking, please refer to the recommendations made in this comment.