CSP report-only cleanup
- Align the Nosecone
Content-Security-Policy-Report-Onlyscript directives with the enforced app CSP for PostHog, Fingerprint, Sentry, and Meta Pixel. - Allow Supabase realtime websocket and blob-worker sources in the report-only policy so Sentry reports actionable violations instead of known-good browser behavior.
- Add regression coverage for Chrome
script-src-elembehavior, script-source parity, Supabase realtime, and worker sources.