A relatively new feature for SharePoint Online is to allow specific Third-Party sources access to execute.
The policy is called Content Security Policy
https://learn.microsoft.com/en-us/sharepoint/dev/spfx/content-securty-policy-trusted-script-sources
One of the requirements is to manually authorized third-party sources.
Can I get a full run down of any URL's rfequired to be "white-listed"?