I do not understand this CORS thing. I suppose it\'s the same as CSRF but for the APIs, but if I don\'t have a stored state, why should I bother with implementing a proper C