The CSP header in the http response should be a site specific configuration, not up to general discourse software, do you know who is responsible for customization of this site?
The content of the header seems heavily customized per discourse.numenta.org site, there has to be someone did this consciously.
If the change you describe was done by Numenta, then it is likely that Matt Taylor had a hand in it.
I can moderate, but this level of tinkering is above my level of permission and I am not able to address the issue.