--- id: 08-app-wiring-web-next epic: security-headers-rate-limit-sbom title: "App wiring: web-next" type: technical-story status: todo feature: web-next depends-on: [07-security-header-adapters] blocks: [] created: 2026-05-20T00:00:00Z updated: 2026-05-20T08:14:55.907Z --- ## Goal Wire the security headers middleware end-to-end in `apps/web-next` — middleware chain, nonce-aware Sentry browser SDK init, and nonce threaded into the document head — producing a Next.js app that emits all six headers with per-request CSP nonces and no CSP violations in the browser console. ## Why `apps/web-next` is the primary template app; getting it wired first validates the Next.js adapter in a real app context, including the Sentry nonce contract and the `