It’s interesting. I’m wondering about this config part
it is completely unknown to me - I also don’t find it in the sample config.
In general you would recommend you remove any custom CSP you add in your reverse proxy, webserver etc. Nextcloud is supposed to generate right CSP itself → csp. After you removed custom CSP stuff review the Collabora integration guide - maybe you find some hints.
I would also give a try to a test server (or spin up a “real” CODE instance for testing) - it looks OxOffice doesn’t receive many updates.. maybe your OxOffice variant is somewhat outdated - version number looks like 3y old Collabora..
Update:
this one is wrong wopi_allowlist should contain IP ranges of your CODE not URLs. Depending on networking config this might be some internal IP or public IP of the CODE system. I recommend to start without any restriction and tighten later.