Description: When I open a monster from the PF2e Bestiary in Chrome, the image for the action type (one action, two action, etc) are prevented from displaying. It displays properly on Firefox. From Logs: /compendium/pf2/Monsters%3ADrow%20Priestess?sharedCompendium=6101378#h-Drow%20Priestess:1 Access to image at '<a href="https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png</a>' from origin '<a href="https://app.roll20.net" rel="nofollow">https://app.roll20.net</a>' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. Steps to reproduce: Go to Conpendium. Search "drow". Open Drow Priestess. Scroll down to Melee __ Rapier. There should be a One action icon there. Settings: Google Chrome Version 80.0.3987.149 Windows 10 JS enabled No additional antivirus (Windows Defender) uBlock Origin (disabled), Reddit Enhancement Suite, Vue Dev Tools, Eye Dropper. Not working on Chrome: Working on Firefox: Console log: (index):12 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'nonce-hHeTdn2mE9kuvfU3' <a href="http://cdn.inspectlet.com" rel="nofollow">http://cdn.inspectlet.com</a> https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a> <a href="http://stun.l.google.com" rel="nofollow">http://stun.l.google.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-rBPYfAszOmE5vzhTF4Hz4hQly2JLl2uhN4tDJLmXbc4='), or a nonce ('nonce-...') is required to enable inline execution. (index):13 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'nonce-hHeTdn2mE9kuvfU3' <a href="http://cdn.inspectlet.com" rel="nofollow">http://cdn.inspectlet.com</a> https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a> <a href="http://stun.l.google.com" rel="nofollow">http://stun.l.google.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-/XHNKTzdVLpPBcMgsOl9LN6PEC5ufZbaLdoU14BWKr0='), or a nonce ('nonce-...') is required to enable inline execution. jquery.migrate.js:20 JQMIGRATE: Logging is active ?timestamp=1586102365&disablewebgl=false&forcelongpolling=false&offsite=false&fbdebug=false&forcetouch=false:15 CAMPAIGN ID: 6101378 app.js?1585829787:552 70 app.js?1585829787:554 TOUCH SUPPORTED: false app.js?1585829787:554 USING WEBGL ACCELERATION... app.js?1585829787:554 WEBGL STARTUP SUCCESS app.js?1585829787:556 Custom Sheet Translation app.js?1585829787:571 Loading Custom character sheet. app.js?1585829787:571 Including compendium template css. tutorial_tips.js:7 tuts loaded (index):1 [DOM] Found 2 elements with non-unique id #color_value: (More info: <a href="https://goo.gl/9p2vKq" rel="nofollow">https://goo.gl/9p2vKq</a>) <input type="text" size="8" id="color_value"> <input type="text" size="8" id="color_value"> sheetsandboxworker.js?1586102367140:682 Starting up WEB WORKER app.js?1585829787:562 Final page load. app.js?1585829787:560 Auth'ed. app.js?1585829787:560 Go post auth! app.js?1585829787:560 initial setup app.js?1585829787:561 joining game... 8app.js?1585829787:558 Full load page! app.js?1585829787:560 We have 8 pages app.js?1585829787:559 Player -M2sJWX_M4PBjcQXocVc is offline... app.js?1585829787:559 Player -M3DDAub_bHL8t74ZtB4 is offline... app.js?1585829787:559 Player -M3SiycGjg-Mj2IKduLG is offline... app.js?1585829787:559 Player -M3XpILhZSW8mRopemuX is offline... app.js?1585829787:559 Player -M3Y2CCaFptidsjQtFDr is offline... app.js?1585829787:561 Deferred finish joining... app.js?1585829787:552 Firebase Online (index):1 [DOM] Found 9 elements with non-unique id #color_value: (More info: <a href="https://goo.gl/9p2vKq" rel="nofollow">https://goo.gl/9p2vKq</a>) <input type="text" size="8" id="color_value"> <input type="text" size="8" id="color_value"> <input type="text" size="8" id="color_value"> <input type="text" size="8" id="color_value"> <input type="text" size="8" id="color_value"> <input type="text" size="8" id="color_value"> <input type="text" size="8" id="color_value"> <input type="text" size="8" id="color_value"> <input type="text" size="8" id="color_value"> 60app.js?1585829787:570 Error while checking for roll total... app.js?1585829787:581 DOMException: Permission denied t.errorLog @ app.js?1585829787:581 (index):1 Access to image at '<a href="https://imgsrv.roll20.net/?src=/images/character.png&cb=5" rel="nofollow">https://imgsrv.roll20.net/?src=/images/character.png&cb=5</a>' from origin '<a href="https://app.roll20.net" rel="nofollow">https://app.roll20.net</a>' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. imgsrv.roll20.net/:1 Failed to load resource: net::ERR_FAILED app.js?1585829787:552 Error loading graphic, probably due to CORS. Trying once without CORS for /images/character.png (anonymous) @ app.js?1585829787:552 DevTools failed to parse SourceMap: <a href="https://app.roll20.net/js/d20/underscore-min.map" rel="nofollow">https://app.roll20.net/js/d20/underscore-min.map</a> (index):1 Invalid 'X-Frame-Options' header encountered when loading '<a href="https://app.roll20.net/compendium/pf2/Monsters%3ADrow%20Priestess?sharedCompendium=6101378#h-Drow%20Priestess" rel="nofollow">https://app.roll20.net/compendium/pf2/Monsters%3ADrow%20Priestess?sharedCompendium=6101378#h-Drow%20Priestess</a>': '<a href="https://app.roll20.net" rel="nofollow">https://app.roll20.net</a>' is not a recognized directive. The header will be ignored. v2.js?1582765325:57 JQMIGRATE: Migrate is installed with logging active, version 3.0.0 v2.js?1582765325:57 JQMIGRATE: jQuery.expr[":"] is now jQuery.expr.pseudos i @ v2.js?1582765325:57 get @ v2.js?1582765325:57 (anonymous) @ v2.js?1582765325:178 Sweetalert2.swal.sweetAlert.Swal.SweetAlert @ v2.js?1582765325:178 (anonymous) @ v2.js?1582765325:178 v2.js?1582765325:57 console.trace i @ v2.js?1582765325:57 get @ v2.js?1582765325:57 (anonymous) @ v2.js?1582765325:178 Sweetalert2.swal.sweetAlert.Swal.SweetAlert @ v2.js?1582765325:178 (anonymous) @ v2.js?1582765325:178 compendium.js?1568130237:650 t.fn.init [div#tableofcontents] /compendium/pf2/Monsters%3ADrow%20Priestess?sharedCompendium=6101378#h-Drow%20Priestess:1 Access to image at '<a href="https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png</a>' from origin '<a href="https://app.roll20.net" rel="nofollow">https://app.roll20.net</a>' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. v2.js?1582765325:50 GET <a href="https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png</a> net::ERR_FAILED M @ v2.js?1582765325:50 css @ v2.js?1582765325:51 Vt @ v2.js?1582765325:51 w @ v2.js?1582765325:50 show @ v2.js?1582765325:51 xt.fn.<computed> @ v2.js?1582765325:51 (anonymous) @ v2.js?1582765325:183 (anonymous) @ jquery-ui.1.11.2.min.js?1483835727:11 (anonymous) @ Monsters%3ADrow Priestess?sharedCompendium=6101378:1323 v2.js?1582765325:57 JQMIGRATE: jQuery.fn.removeAttr no longer sets boolean properties: required i @ v2.js?1582765325:57 (anonymous) @ v2.js?1582765325:57 each @ v2.js?1582765325:50 t.fn.removeAttr @ v2.js?1582765325:57 buildDom @ typeahead.js?1483835727:1652 Typeahead @ typeahead.js?1483835727:1458 attach @ typeahead.js?1483835727:1708 each @ v2.js?1582765325:50 each @ v2.js?1582765325:50 initialize @ typeahead.js?1483835727:1702 $.fn.typeahead @ typeahead.js?1483835727:1774 (anonymous) @ compendium.js?1568130237:233 h @ v2.js?1582765325:51 d @ v2.js?1582765325:51 setTimeout (async) (anonymous) @ v2.js?1582765325:51 u @ v2.js?1582765325:51 fireWith @ v2.js?1582765325:51 fire @ v2.js?1582765325:51 u @ v2.js?1582765325:51 fireWith @ v2.js?1582765325:51 ready @ v2.js?1582765325:51 d @ v2.js?1582765325:50 v2.js?1582765325:57 console.trace i @ v2.js?1582765325:57 (anonymous) @ v2.js?1582765325:57 each @ v2.js?1582765325:50 t.fn.removeAttr @ v2.js?1582765325:57 buildDom @ typeahead.js?1483835727:1652 Typeahead @ typeahead.js?1483835727:1458 attach @ typeahead.js?1483835727:1708 each @ v2.js?1582765325:50 each @ v2.js?1582765325:50 initialize @ typeahead.js?1483835727:1702 $.fn.typeahead @ typeahead.js?1483835727:1774 (anonymous) @ compendium.js?1568130237:233 h @ v2.js?1582765325:51 d @ v2.js?1582765325:51 setTimeout (async) (anonymous) @ v2.js?1582765325:51 u @ v2.js?1582765325:51 fireWith @ v2.js?1582765325:51 fire @ v2.js?1582765325:51 u @ v2.js?1582765325:51 fireWith @ v2.js?1582765325:51 ready @ v2.js?1582765325:51 d @ v2.js?1582765325:50