Hi Franky, Here's the entire log from opening my game up to click on the little lock icon - thanks for any help! Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a> <a href="http://stun.l.google.com" rel="nofollow">http://stun.l.google.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-1Ekk+2sOz2rpPzkjnWi8qbhAAcUsDkukzA3KOGe4DDQ='), or a nonce ('nonce-...') is required to enable inline execution. Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a> <a href="http://stun.l.google.com" rel="nofollow">http://stun.l.google.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-g/RZo8vf07Pu8/gSqYdWwmd3NQYKzaVylxDWr2JAUf0='), or a nonce ('nonce-...') is required to enable inline execution. 70 TOUCH SUPPORTED: false USING WEBGL ACCELERATION... WEBGL STARTUP SUCCESS Custom Sheet Translation select Switch mode to select Initializing new dice engine with randomness... Using random entropy Unable to start up OpenTok! Compiling sheet... Found rolltemplate: simple Found rolltemplate: atk Found rolltemplate: dmg Found rolltemplate: atkdmg Found rolltemplate: desc Found rolltemplate: spell Found rolltemplate: npc Found rolltemplate: npcatk Found rolltemplate: npcdmg Found rolltemplate: npcaction Found webworker script Finding sheet rolls... window resize Final set zoom! UPDATE GL SIZE! Final set zoom! tuts loaded Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png</a>'. This content should also be served over HTTPS. Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/3OxOqmb.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/3OxOqmb.png</a>'. This content should also be served over HTTPS. Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png</a>'. This content should also be served over HTTPS. Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/py5B0cm.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/py5B0cm.png</a>'. This content should also be served over HTTPS. Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/LoT21n1.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/LoT21n1.png</a>'. This content should also be served over HTTPS. Starting up WEB WORKER Starting up WEB WORKER Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a> <a href="http://stun.l.google.com" rel="nofollow">http://stun.l.google.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-q+ohWFnh22teYcdFqeh0e7HJqlsXF+SksNUnF330c+c='), or a nonce ('nonce-...') is required to enable inline execution. Failed to load resource: net::ERR_BLOCKED_BY_CLIENT Failed to load resource: net::ERR_BLOCKED_BY_CLIENT Final page load. Refresh jukebox List! Auth'ed. Go post auth! initial setup T.r Got players value... joining game... Player -KUHX4SyR8fRWsQOpcoe is offline... Global Volume: 100=1 Player -KUNHzkZuhHSP1DTdCVb is offline... Player -KUNM0wLrlkIBQBOZHFN is offline... Player -KUllRVOPO_cQrL_fM08 is offline... Deferred finish joining... Firebase Online refershing page listings! Full load page! We have 49 pages Scan for new plays! handle page changes false INITIATLIZING INTERNAL VIDEO CHAT Refresh jukebox List! Do refresh link cache! init active page! activate page! FULLY ACTIVATE VIEWS FOR PAGE. Refresh Journal List! Search took 232ms Reorder by ZORDER Swapping <a href="https://s3.amazonaws.com/files.d20.io/marketplace/170633/J2OaVw5AY5dKwDwswLk6pg/thumb.jpg?1471982860&14726694485" rel="nofollow">https://s3.amazonaws.com/files.d20.io/marketplace/170633/J2OaVw5AY5dKwDwswLk6pg/thumb.jpg?1471982860&14726694485</a> to <a href="https://s3.amazonaws.com/files.d20.io/marketplace/170633/J2OaVw5AY5dKwDwswLk6pg/max.jpg?1471982860&14726694485" rel="nofollow">https://s3.amazonaws.com/files.d20.io/marketplace/170633/J2OaVw5AY5dKwDwswLk6pg/max.jpg?1471982860&14726694485</a> setting src Cols: 2 Rows: 1 Took 1ms to generate cache. Graphics: 1 Paths: 1 refershing page listings! Reorder by ZORDER handle page changes false init active page! activate page! FULLY ACTIVATE VIEWS FOR PAGE. Graphics: 1 Paths: 1 Reorder by ZORDER refershing page listings! Show Character View Dialog! --- RENDER CHARACTIVE VIEW ---- CLICKED Redoing charsheet html 110ms to end of html 239 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png</a>'. This content should also be served over HTTPS. Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/3OxOqmb.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/3OxOqmb.png</a>'. This content should also be served over HTTPS. Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png</a>'. This content should also be served over HTTPS. Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/py5B0cm.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/py5B0cm.png</a>'. This content should also be served over HTTPS. Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/LoT21n1.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/LoT21n1.png</a>'. This content should also be served over HTTPS. Really updating character sheet values Triggering for sheet:opened Foudn a pre-defined key order! Setting up repeating sections took until 75ms Updating ALL VALUES Finding list of dirty attributes took until 76ms Querytest took until 77ms Attribute cache compliation took until 78ms Set values (including auto-calcuating variables) took until 223ms Appending to sheetform Appending to screen took until 263ms Took 276ms Triggering for sheet:opened 5th Edition OGL by Roll20 version 1.6 5th Edition OGL by Roll20 version 1.6 window resize Final set zoom! UPDATE GL SIZE! Final set zoom! CLICKED Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://i.imgur.com/vpXpRej.png" rel="nofollow">http://i.imgur.com/vpXpRej.png</a>'. This content should also be served over HTTPS. CLICKED: radio/checkbox <input class="sheet-tab-button sheet-spells" type="radio" name="attr_tab" value="spells" checked="checked"> input type radio value = "spells" CLICKED Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://i.imgur.com/S9giK7M.png" rel="nofollow">http://i.imgur.com/S9giK7M.png</a>'. This content should also be served over HTTPS. CLICKED Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://i.imgur.com/9WZKlVy.png" rel="nofollow">http://i.imgur.com/9WZKlVy.png</a>'. This content should also be served over HTTPS.