About Content Security Policy settings and CDNs
### Content Security Policy (CSP)

By default, Hanami sets a Content-Security-Policy header which does not allow for the execution of external JavaScript code.

Let's say we want to use [Bootstrap]( in our `web` application, we have to explicitly allow for the use of the relevant CDNs in `app/web/application.rb` by appending them in the `script-src` field:

security.content_security_policy %{
script-src 'self' \ \ \;

Read more about the CSP header in the [security guide](/guides/1.1/projects/security/#content-security-policy).

### Local Assets

The security problem described above doesn't concern only CDNs, but local files too.

