I would recommend to start with
default-src 'self' 'unsafe-inline' 'unsafe-eval'
Ideally, you wouldn't want to include the unsafe options, but unfortunately the Mendix platform needs it to run properly.
Next step is to check if extra sources need to be added, depending on your needs.