The browser console is hitting some errors due to content security policy on a Rails 7.0.3 application when running connections to localhost:3000.
Rails.application.config.content_security_policy do |policy|
# policy.default_src :self, :https
policy.font_src :self, :https, :data
policy.img_src :self, :https, :data
policy.object_src :none
policy.style_src :self, :https, :unsafe_inline
policy.connect_src :self, :https, 'https://api.stripe.com'
policy.frame_src :self, 'https://js.stripe.com', 'https://hooks.stripe.com'
# policy.script_src :self, :https #, :unsafe_inline
end
Under the above settings the application does not encounter any errors.

The moment one of the two disabled policies is enabled, page settings block elements Content Security Policy: The page's settings blocked the loading of a resource at inline ("script-src"). The peculiar part is that it occurs even with default settings 
policy.script_src :self, :https
Also, it is weird that default_src would also lead to blocking of said resource...
[side note] no idea how to get this suggestion to function, the path being a rails-compliant route definition
# Specify URI for violation reports
# policy.report_uri "/csp-violation-report-endpoint"
The first line points to the place where the first object is blocked, essentially the application importmap thus disabling hotwire.
wonderful!
The question is a bit fuzzy (knowledge of csp combined with the mechanics of Rails and importmaps in this instance being limited). The full set of policies are running on a Rails 6 application; Rails 7 has the obvious change of importmaps to do things the Hotwire way. The lack of a CSP, especially regarding scripts, is logically frowned upon.
So how does Hotwire get to run with proper settings?