Im having trouble with accessing a http response's cookies. According to Postman, it is getting sent as shown here:

And this is what the requests looks like according to Google Chrome's network developer tab: Google Chrome's Network Tab
Here is the code that I use to send the get request:
createAuthorizationHeader(headers: Headers, user:String, pass:String) {
headers.append('Authorization', 'Basic ' +
btoa(user+":"+pass));
headers.append('Content-Type', 'application/json');
}
login() {
var user = this.username.nativeElement.value;
var pass = this.password.nativeElement.value;
let header = new Headers();
this.createAuthorizationHeader(header, user, pass);
let options = new RequestOptions({ headers: header, withCredentials: true });
this.http.get('http://localhost:8080/sample-webapp/rest/auth/login', options)
.subscribe(res => {
console.log(res);
console.log(res.headers.get('Set-Cookie'));
});
}
After looking it up for a while, withCredentials: true was supposed to fix my issue and include the cookie in the response header. But all I get is this:

It doesn't seem like a backend issue cause the cookie is received by the Browser and Postman. Please let me know what I can do to get my yummy cookies?
Also the backend has the following headers:
response.getHeaders().add("Access-Control-Allow-Origin", request.getHeaderString("origin"));
response.getHeaders().add("Access-Control-Allow-Headers", request.getHeaderString("access-control-request-headers"));
response.getHeaders().add("Access-Control-Allow-Credentials", "true");
response.getHeaders().add("Access-Control-Expose-Headers", "Set-Cookie");
response.getHeaders().add("Access-Control-Allow-Methods", request.getHeaderString("access-control-request-method"));