Add a Content Security Policy header for each request, with optional nonces that are passed into Twig