Performance and transport-layer hardening.
ImageUploader.tsx:
- Replaced sequential for-loop uploads with Promise.allSettled, so
multiple files upload concurrently. Partial failures no longer abort
the whole batch — successful uploads are kept, failed ones surface
a concatenated error (and a subsequent retry is still possible).
- Order indices are pre-computed from the existing images.length so
the parallel results stay correctly ordered.
next.config.ts:
- PoweredByHeader: false (no longer advertises Next.js).
- compress: true explicitly (default, but documented).
- Added Strict-Transport-Security, X-Frame-Options, X-Content-Type-
Options, Referrer-Policy, Permissions-Policy and a defensive CSP
(script-src allows 'unsafe-eval' for Next.js dev/HMR invariants,
connect-src whitelists Clerk endpoints).
- remotePatterns is now only populated when S3_ENDPOINT is set, and
parsed with URL() so a trailing path no longer produces a phantom
hostname. Still effectively unused because the app uses raw <img>;
the migration to next/image is deferred.