Full CSP (content-security-policy-report-only)

x-nonce header:
a725ba98-1a99-487f-bc0f-84ca2fcbe0e0
content-security-policy-report-only header:
default-src 'self'; script-src 'report-sample' 'self' 'nonce-a725ba98-1a99-487f-bc0f-84ca2fcbe0e0' 'strict-dynamic'; style-src 'report-sample' 'self' 'nonce-a725ba98-1a99-487f-bc0f-84ca2fcbe0e0'; connect-src 'self' *.vercel-insights.com plausible.io; font-src 'self' data:; img-src 'self' data:; worker-src 'self' blob:; frame-ancestors 'none'; form-action 'self'

Full CSP | Report Only | Pages router example