Having the same problem, I found the solution on https://content-security-policy.com
A pattern like https://*.openstreetmap.org is not valid, because "*" is not at the beginning !
But *.openstreetmap.org is valid and does the job.