Questions
The Vary: Origin (or omitting it) is now used based on the configured CORS.
Another use would be Vary: Accept, (and maybe also Accept-Encoding and Accept-Language), to ensure caching (if applicable) is considered for different response content representations on the same HTTP method / URL.
Should these be set by default across the server?
Should it be a separate variable, which would then be combined with the other Vary: Origin auto-computed?
References