1. response.setHeader("Access-Control-Allow-Origin", "*"); 2. @CrossOrigin(origins = "*",maxAge = 3600)