Astro CSP
Astro CSP is validated by production build and preview.
Use hash-based CSP. Avoid unsafe-inline. Any external asset source must be explicitly listed and reviewed.
Development Binding
Section titled “Development Binding”Frontend scripts must not hardcode bind addresses or ports.
Allowed runtime env:
ASTRO_DEV_HOSTASTRO_DEV_PORTASTRO_PREVIEW_HOSTASTRO_PREVIEW_PORTASTRO_HOSTASTRO_PORT
Development stage routing is owned by assembly Traefik labels and Mutagen forwarding.