Add the Access-Control-Allow-Methods header so that DELETE operations are allowed. Also move the write CORS headers method before docker writes a 404 not found so that the client receives the correct response and not an invalid CORS request. Upstream-commit: 393e873d25093f579d1a293bc473007b04f3c239 Component: engine