If both Kong and the upstream add Access-Control-Allow-Origin, the browser sees two values in one header and rejects the response outright. The symptom is a CORS error on a request that has CORS configured twice.
Run this yourself in the Online Java Compiler, spin up a live REST API in the API Sandbox, or practise with Java interview questions.
Published 2026-08-25