If the ACL middleware throws an exception, it's not annotated
by CORS, preventing the browser from seeing the auth error.
This patch reverses the order and makes sure even auth
error responses are annotated.
Change-Id: Ie2c05fe6a7f1eb341707311d6452aaf01b4790b3