To enable the generation of Content-Security-Policy headers for your SSR
content, you have to set the option securityHeaders.contentSecurityPolicy to
a non-null object.
If you want more control, then you can set other nested options, such as
cspDirectives.