The CSP should not be alerted by the serving software (be it Apache, Nix, or any other). This is the job of the Nextcloud PHP code.
There might be reasons for putting more or less restrictive headers there depending on the use case. In fact the app can individually decide, which headers to send. By “repairing” the headers in such a crude manner, you have no clue what security issues might arise.
So, again, for all those that found the topic: do not replace the security related headers like CSP without explicit knowledge and need. I just wrote this to avoid such an work to be made by anyone.
The problem with security is: unless you test it (and you know how to test it), it seems to work. Your users are happy. No one complains, not even the hackers . You only see the problem later when something nasty has happened.
If there was the need to do such a thing, this is either a bug (which should be reported and fixed in the first place) or a use case that was never considered yet (and should be brought to the devs awareness). There might be workaround to be installed but that would be much more narrowed down and must be replaced after fixing.
Just chiming in to make it very clear and reiterate what Christian said: CSP is managed dynamically by Nextcloud Server. Do not set the header statically like this yourself.
If the header is missing, something is misconfigured in your environment (e.g. an RP/web server is clearing and not passing on headers).
Also, as a reminder, security matters have their own reporting channel. Every repository within the project on GitHub has a Security Policy link. Or you can visit the one in the main repository directly.