We allow CORS and expose the Authorization header by default. If you want to disable it, you can comment out the contents of the config/cors.rb file.
config/cors.rb