CORS error when adding "x-csrf-token" request header

headers: new Headers({ ‘x-csrf-token’: csrf })

This might be overwriting all your headers, causing the CORS check on your server to fail. You might want to check if your server is receiving the request with the Origin header or anything else it needs to validate the request.