In the documentation have a list of critical third-party domains vanilla Codoforum will need to connect to for features to work
An example of a domain i'd say is critical:
https://unpkg.com/vue@next is a example of something i would say is a critical third party domain as if Codoforum is unable to connect to it, then the "Edit Badges" page will not load.
Why this is important:
Codoforum gives the right to self-host forums if you opt for the free plan. (All forum features cannot remove Powered by) (source).
As someone who self-hosts an install of Codoforum myself (Configured an Ubunutu Server myself, setup web server, maintenance, security) I also have to configure the content security policies. And if Codoforum gave a list domains to add to the list so Codoforum works without issue then it'd remove the headache of figuring out which some features do not work (as example from above, the badges not working if https://unpkg.com/vue@next is not whitelisted, Freichat not working if https://nodelb.freichat.com also is not whitelisted, and so on.