Your CSP probably does nothing
A Content-Security-Policy with an allowlist in it is usually bypassable, and the directives that stop the bypass are the ones nobody writes because nothing breaks when they are missing. What a policy actually has to contain, and why the good ones still get rolled back.