T3395
Add recommended headers.
Note: CSP header is added as 'report-only' so that we can confirm it does not break the site.
ref
https://nextjs.org/docs/pages/api-reference/next-config-js/headers
https://github.com/vercel/next.js/discussions/17991 for `source:` key to cover whole site