What CSPs to set on Atlassian Connect apps

There is the (now closed) RFC-35: Custom Domains Support For Confluence - #42 by JohnHooper , however in this discussion Atlassian says:

So I’m not aware of Atlassian guidance how vendors should handle the CSP for custom domains.