**Description** Apply CORS, ETag/HTTP caching, pagination defaults, and timeouts. **Acceptance Criteria** - [ ] CORS config per environment - [ ] ETag/Last-Modified and cache headers where safe - [ ] Sensible pagination defaults and max caps - [ ] Request timeouts and connection pooling