Update koha-conf-site.xml.in to include a report-only CSP policy for opac and intranet
Include a report-only CSP configuration in koha-conf-site.xml.in so that KTD uses CSP out of the box once "Bug 38365 - Add Content-Security-Policy HTTP header to HTML responses" is pushed