Why aren't there security header on a Static Web App first load of html ?
Anonymous
Why aren't there security header on the first html request for a Static web apps ?
We are using the "staticwebapp.config.json" file for settings the headers.
We are hosting a next.js app.
The first html request: 
Other request for JS/CSS/Icons:
Azure Static Web Apps
Azure Static Web Apps
An Azure service that provides streamlined full-stack web app development.
Sign in to answer