I carefully examined the bits of the CORS spec (edition http://www.w3.org/TR/2010/WD-cors-20100727/ ) relevant to the Access-Control-Request-Header.
Could you please review http://dev.w3.org/2006/waf/access-control/ instead? The TR/ version is (always) out of date.
-- Anne van Kesteren http://annevankesteren.nl/
