environment('local')) { // Relaxed CSP for local development with Vite $csp = "script-src 'self' 'unsafe-inline' 'unsafe-eval' http: https:; " . "style-src 'self' 'unsafe-inline' http: https:; " . "connect-src 'self' ws: http: https:;"; } else { // Production CSP - Livewire v3 requires unsafe-eval $csp = "script-src 'self' 'unsafe-eval' https:; " . "style-src 'self' 'unsafe-inline' https:; " . "connect-src 'self' https:;"; } $response->headers->set('Content-Security-Policy', $csp); return $response; } }