Exercise 1: A Real CORS Middleware — Possible Solution ==================================================================== THE MIDDLEWARE ------------------------------ def cors_middleware(request, next_): response = next_(request) response.headers.append(('Access-Control-Allow-Origin', '*')) return response app = App() app.use(cors_middleware) app.add_route('GET', '/', lambda req: Response('ok')) VERIFIED, REAL RESULT ------------------------------ A real live GET request to '/', served through wsgiref, comes back with: status: 200 Access-Control-Allow-Origin: * read directly from the response object's own real headers dict on the client side, not just inspected on the server before sending. WHY THIS WORKS AS AN ANSWER ------------------------------ It places the header-append AFTER next_() returns, matching the chapter's own "after next_(), mutate the response" pattern exactly (the timing middleware does the identical thing to response.headers), and verifies the header on the real client-received response rather than only checking the Response object locally before it's ever sent through to_wsgi().