Tried joining my first campaign tonight, joined the google hangout first, installed the app, then got the email to join the campaign. I receive the same error on multiple browsers and multiple computers, however all on the same internet connection. Below is the console data from an attempt on a mac, OS X 10.7.5, most recent version of Chrome. This was copied after clearing my cache, removing extensions, and a reboot. Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net https://*.googlesyndication.com <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> https://*.googlesyndication.com <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> https://*.googlesyndication.com <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.googlesyndication.com https://*.tokbox.com https://*.googlesyndication.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution. app.roll20.net/:9 Resource interpreted as Script but transferred with MIME type text/html: " <a href="https://app.roll20.net/editor/startjs/?timestamp=1409798541&disablewebgl=false&forcelongpolling=false&offsite=false" rel="nofollow">https://app.roll20.net/editor/startjs/?timestamp=1409798541&disablewebgl=false&forcelongpolling=false&offsite=false</a> ". app.roll20.net/:15 70 app.js?1409778770:22 TOUCH SUPPORTED: false app.js?1409778770:23 USING WEBGL ACCELERATION... app.js?1409778770:23 select app.js?1409778770:18 Switch mode to select app.js?1409778770:18 Initializing new dice engine with randomness... app.js?1409778770:32 Using random entropy app.js?1409778770:32 window resize app.js?1409778770:35 Final set zoom! app.js?1409778770:23 UPDATE GL SIZE! app.js?1409778770:23 Final set zoom! app.js?1409778770:23 tuts loaded tutorial_tips.js:7 Refused to execute JavaScript URL because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net https://*.googlesyndication.com <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> https://*.googlesyndication.com <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> https://*.googlesyndication.com <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.googlesyndication.com https://*.tokbox.com https://*.googlesyndication.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution. pubads_impl_48.js:115 Refused to execute JavaScript URL because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net https://*.googlesyndication.com <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> https://*.googlesyndication.com <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> https://*.googlesyndication.com <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.googlesyndication.com https://*.tokbox.com https://*.googlesyndication.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution. pubads_impl_48.js:115 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net https://*.googlesyndication.com <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> https://*.googlesyndication.com <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> https://*.googlesyndication.com <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.googlesyndication.com https://*.tokbox.com https://*.googlesyndication.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution. pubads_impl_48.js:119 Final page load. app.js?1409778770:28 Scan for new plays! app.js?1409778770:28 Auth'ed. app.js?1409778770:28 Go post auth! app.js?1409778770:28 4Scan for new plays! app.js?1409778770:28 initial setup app.js?1409778770:28 Got players value... app.js?1409778770:28 joining game... app.js?1409778770:28 ERROR: NO EXISTING PLAYER app.js?1409778770:28 No active player, returning... app.js?1409778770:28 Player -IkN-lxGTmNZLLkiy-Ae is offline... app.js?1409778770:26 Player -Itw_REPRRFNklKB5oWj is offline... app.js?1409778770:26 Player -IkN-s8oAnwsGKf2n2Kc is offline... app.js?1409778770:26 Player -InkG1DYOmRe4Dv55rH0 is offline... app.js?1409778770:26 5Full load page! app.js?1409778770:26 We have 5 pages app.js?1409778770:28 Refused to execute inline event handler because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net https://*.googlesyndication.com <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> https://*.googlesyndication.com <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> https://*.googlesyndication.com <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.googlesyndication.com https://*.tokbox.com https://*.googlesyndication.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution. app.roll20.net/:1 The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but displayed insecure content from ' <a href="http://imgsrv.roll20.net:5100/?src=www.dundjinni.com/forums/uploads/RPMiller/FEB_BlueWhiteMan_RPM.png&cb=5" rel="nofollow">http://imgsrv.roll20.net:5100/?src=www.dundjinni.com/forums/uploads/RPMiller/FEB_BlueWhiteMan_RPM.png&cb=5</a> ': this content should also be loaded over HTTPS. app.roll20.net/:1 The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but displayed insecure content from ' <a href="http://imgsrv.roll20.net:5100/?src=1.bp.blogspot.com/-RCP8yt3mP_4/T2TgA-HEN7I/AAAAAAAAAEo/Oh-zhAmbda0/s1600/reavers.jpg&cb=5" rel="nofollow">http://imgsrv.roll20.net:5100/?src=1.bp.blogspot.com/-RCP8yt3mP_4/T2TgA-HEN7I/AAAAAAAAAEo/Oh-zhAmbda0/s1600/reavers.jpg&cb=5</a> ': this content should also be loaded over HTTPS. app.roll20.net/:1 The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but displayed insecure content from ' <a href="http://imgsrv.roll20.net:5100/?src=2.bp.blogspot.com/-9Q3IoPLxVjc/T5qNuw_S6CI/AAAAAAAAA4k/hqWRU9vfU5g/s1600/yacht.jpg&cb=5" rel="nofollow">http://imgsrv.roll20.net:5100/?src=2.bp.blogspot.com/-9Q3IoPLxVjc/T5qNuw_S6CI/AAAAAAAAA4k/hqWRU9vfU5g/s1600/yacht.jpg&cb=5</a> ': this content should also be loaded over HTTPS. app.roll20.net/:1 The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but displayed insecure content from ' <a href="http://imgsrv.roll20.net:5100/?src=previewcf.turbosquid.com/Preview/2013/09…_03_15_13/drillLS1.png08901f8a-9343-4310-8dde-ae06db6cf35eLarge.jpg&cb=555" rel="nofollow">http://imgsrv.roll20.net:5100/?src=previewcf.turbosquid.com/Preview/2013/09…_03_15_13/drillLS1.png08901f8a-9343-4310-8dde-ae06db6cf35eLarge.jpg&cb=555</a> ': this content should also be loaded over HTTPS. app.roll20.net/:1 The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but displayed insecure content from ' <a href="http://imgsrv.roll20.net:5100/?src=1.bp.blogspot.com/-RCP8yt3mP_4/T2TgA-HEN7I/AAAAAAAAAEo/Oh-zhAmbda0/s1600/reavers.jpg&cb=5" rel="nofollow">http://imgsrv.roll20.net:5100/?src=1.bp.blogspot.com/-RCP8yt3mP_4/T2TgA-HEN7I/AAAAAAAAAEo/Oh-zhAmbda0/s1600/reavers.jpg&cb=5</a> ': this content should also be loaded over HTTPS. app.roll20.net/:1 The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but displayed insecure content from ' <a href="http://imgsrv.roll20.net:5100/?src=2.bp.blogspot.com/-9Q3IoPLxVjc/T5qNuw_S6CI/AAAAAAAAA4k/hqWRU9vfU5g/s1600/yacht.jpg&cb=5" rel="nofollow">http://imgsrv.roll20.net:5100/?src=2.bp.blogspot.com/-9Q3IoPLxVjc/T5qNuw_S6CI/AAAAAAAAA4k/hqWRU9vfU5g/s1600/yacht.jpg&cb=5</a> ': this content should also be loaded over HTTPS. app.roll20.net/:1 Resource interpreted as Image but transferred with MIME type binary/octet-stream: " <a href="https://s3.amazonaws.com/files.d20.io/images/72344/v5Z3RIuOUvIbXlKGdOMHxA/thumb.png?13412955355" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/72344/v5Z3RIuOUvIbXlKGdOMHxA/thumb.png?13412955355</a> ". Resource interpreted as Image but transferred with MIME type binary/octet-stream: " <a href="https://s3.amazonaws.com/files.d20.io/marketplace/6269/yW7ckcLlEF1hRSd9KvQ8TA/max.png?13403201935" rel="nofollow">https://s3.amazonaws.com/files.d20.io/marketplace/6269/yW7ckcLlEF1hRSd9KvQ8TA/max.png?13403201935</a> ". Resource interpreted as Image but transferred with MIME type binary/octet-stream: " <a href="https://s3.amazonaws.com/files.d20.io/marketplace/6211/PxbgsgU8H6W4R82ytug8MQ/thumb.png?134031715255" rel="nofollow">https://s3.amazonaws.com/files.d20.io/marketplace/6211/PxbgsgU8H6W4R82ytug8MQ/thumb.png?134031715255</a> ". Reorder by ZORDER app.js?1409778770:26 Resource interpreted as Image but transferred with MIME type binary/octet-stream: " <a href="https://s3.amazonaws.com/files.d20.io/marketplace/5435/max.png?13395978435" rel="nofollow">https://s3.amazonaws.com/files.d20.io/marketplace/5435/max.png?13395978435</a> ". Reorder by ZORDER app.js?1409778770:26 Resource interpreted as Image but transferred with MIME type binary/octet-stream: " <a href="https://s3.amazonaws.com/files.d20.io/images/169976/BOElD6wAjjT5Ldw7mF61-Q/thumb.png?13457997955" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/169976/BOElD6wAjjT5Ldw7mF61-Q/thumb.png?13457997955</a> ". Uncaught TypeError: Cannot read property 'id' of undefined app.js?1409778770:25 Resource interpreted as Image but transferred with MIME type binary/octet-stream: " <a href="https://s3.amazonaws.com/files.d20.io/images/2782025/I-M8-gfrfeLZrgmTgBN1pQ/max.png" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/2782025/I-M8-gfrfeLZrgmTgBN1pQ/max.png</a> ". Reorder by ZORDER app.js?1409778770:26 Swapping <a href="https://s3.amazonaws.com/files.d20.io/marketplace" rel="nofollow">https://s3.amazonaws.com/files.d20.io/marketplace</a>... to <a href="https://s3.amazonaws.com/files.d20.io/marketplace" rel="nofollow">https://s3.amazonaws.com/files.d20.io/marketplace</a>... app.js?1409778770:25 Reorder by ZORDER app.js?1409778770:26 The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but displayed insecure content from ' <a href="http://imgsrv.roll20.net:5100/?src=previewcf.turbosquid.com/Preview/2013/09…_03_15_13/drillLS1.png08901f8a-9343-4310-8dde-ae06db6cf35eLarge.jpg&cb=555" rel="nofollow">http://imgsrv.roll20.net:5100/?src=previewcf.turbosquid.com/Preview/2013/09…_03_15_13/drillLS1.png08901f8a-9343-4310-8dde-ae06db6cf35eLarge.jpg&cb=555</a> ': this content should also be loaded over HTTPS. app.roll20.net/:1 Resource interpreted as Image but transferred with MIME type application/xml: " <a href="http://imgsrv.roll20.net:5100/?src=previewcf.turbosquid.com/Preview/2013/09…_03_15_13/drillLS1.png08901f8a-9343-4310-8dde-ae06db6cf35eLarge.jpg&cb=555" rel="nofollow">http://imgsrv.roll20.net:5100/?src=previewcf.turbosquid.com/Preview/2013/09…_03_15_13/drillLS1.png08901f8a-9343-4310-8dde-ae06db6cf35eLarge.jpg&cb=555</a> ". Error loading image, probably due to cors. Trying once without CORS for <a href="http://d20cors.herokuapp.com/?src=previewcf.turbo" rel="nofollow">http://d20cors.herokuapp.com/?src=previewcf.turbo</a>... app.js?1409778770:22 The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but displayed insecure content from ' <a href="http://d20cors.herokuapp.com/?src=previewcf.turbosquid.com/Preview/2013/09/…__03_15_13/drillLS1.png08901f8a-9343-4310-8dde-ae06db6cf35eLarge.jpg&cb=55" rel="nofollow">http://d20cors.herokuapp.com/?src=previewcf.turbosquid.com/Preview/2013/09/…__03_15_13/drillLS1.png08901f8a-9343-4310-8dde-ae06db6cf35eLarge.jpg&cb=55</a> ': this content should also be loaded over HTTPS. app.roll20.net/:1 Swapping <a href="https://s3.amazonaws.com/files.d20.io/marketplace" rel="nofollow">https://s3.amazonaws.com/files.d20.io/marketplace</a>... to <a href="https://s3.amazonaws.com/files.d20.io/marketplace" rel="nofollow">https://s3.amazonaws.com/files.d20.io/marketplace</a>... app.js?1409778770:25 Resource interpreted as Image but transferred with MIME type binary/octet-stream: " <a href="https://s3.amazonaws.com/files.d20.io/marketplace/6269/yW7ckcLlEF1hRSd9KvQ8TA/thumb.png?13403201935" rel="nofollow">https://s3.amazonaws.com/files.d20.io/marketplace/6269/yW7ckcLlEF1hRSd9KvQ8TA/thumb.png?13403201935</a> ". setting src app.js?1409778770:25 Reorder by ZORDER app.js?1409778770:26 Resource interpreted as Image but transferred with MIME type binary/octet-stream: " <a href="https://s3.amazonaws.com/files.d20.io/marketplace/5435/thumb.png?13395978435" rel="nofollow">https://s3.amazonaws.com/files.d20.io/marketplace/5435/thumb.png?13395978435</a> ". GET <a href="http://d20cors.herokuapp.com/?src=previewcf.turbo" rel="nofollow">http://d20cors.herokuapp.com/?src=previewcf.turbo</a>... 503 (Service Unavailable) d20cors.herokuapp.com/:1 setting src app.js?1409778770:25 Thanks for the help. EDIT: Here's the campaign link: <a href="https://app.roll20.net/campaigns/details/66003/andrews-online-game-2013" rel="nofollow">https://app.roll20.net/campaigns/details/66003/andrews-online-game-2013</a>