Access-Control-Allow-Origin

You shouldn't need to edit red.js - we added httpAdminMiddleware in the last release which would allow you to do this via your settings file.

Regardless, it looks like something is overwriting the header somewhere else in the stack. You'd need to trace it through to see what's doing that