As these things usually go, simply writing things down generally allows for faster progress and I made some more.

To /etc/apache2/sites-available/000-default.conf, just before the line, I added

RequestHeader append Origin "mirror 12"

and this got me past the Origin if statement in add_cors and the “Origin header is allowed under the CORS policy…” debug message shows up and everything appears to be generally working.

So, SUCCESS!

However, hacking in a Origin request header seems, well, hackish and I have to think there is a better way.

Any insights into this would be appreciated.