CSP connect-src Should Be a Small Network Allowlist
Browser-side health checks needed cross-origin access, but the fix was two explicit origins rather than a broad wildcard.
Browser-side health checks needed cross-origin access, but the fix was two explicit origins rather than a broad wildcard.
Browser security policy is part of application behavior; a blocked fetch can make a healthy backend look unreachable.