The API should probably be Response.setAccessControlMaxAge. It would also be nice if the CorsFilter and CorsService supported this.