Content-Security-Policy in Next.js: Environment-Aware Headers, connect-src Rules, and Realtime Pitfalls
Content-Security-Policy gets treated as a box to check: paste a template from OWASP, sprinkle a few nonces, call it secure. But in modern application stacks, especially ones built on the Next.js App Router, React Server Components, and real-time GraphQL connections, a static CSP isn't just insufficient, it&