- Modified the Content-Security-Policy to include specific domains for default-src and connect-src, improving security and flexibility. - Updated the commented-out Content-Security-Policy in the _headers file to reflect the same changes for consistency.