Fix: Added CORS header to REST API to allow cross-domain calls from modern browsers.