Implement Content-Security-Policy headers and strict content-type handling
for non-API responses, with x-content-type-options applied to all routes.
Adds security-headers test suite to verify header presence.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>