As these things usually go, simply writing things down generally allows for faster progress and I made some more.
To /etc/apache2/sites-available/000-default.conf, just before the line, I added
RequestHeader append Origin "mirror 12"
and this got me past the Origin if statement in add_cors and the “Origin header is allowed under the CORS policy…” debug message shows up and everything appears to be generally working.
So, SUCCESS!
However, hacking in a Origin request header seems, well, hackish and I have to think there is a better way.
Any insights into this would be appreciated.