cors origins setting is controlled in admin > settings > security
cors origins
admin > settings > security
you only need DISCOURSE_ENABLE_CORS: in your app.yml
DISCOURSE_ENABLE_CORS: