1 Commits

Author SHA1 Message Date
marcuspaico
876aa0f181 feat(security): CSP and hardening headers with upload serving
Implement Content-Security-Policy headers and strict content-type handling
for non-API responses, with x-content-type-options applied to all routes.
Adds security-headers test suite to verify header presence.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-17 16:06:05 -07:00