Roll20 uses cookies to improve your experience on our site. Cookies enable you to enjoy certain features, social sharing functionality, and tailor message and display ads to your interests on our site and others. They also help us understand how our site is being used. By continuing to use our site, you consent to our use of cookies. Update your cookie preferences .
×
Create a free account

Pathfinder 2e Bestiary Action Icons not displayed on Chrome

Description: When I open a monster from the PF2e Bestiary in Chrome, the image for the action type (one action, two action, etc) are prevented from displaying. It displays properly on Firefox.&nbsp; From Logs:&nbsp;/compendium/pf2/Monsters%3ADrow%20Priestess?sharedCompendium=6101378#h-Drow%20Priestess:1 Access to image at '<a href="https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png</a>' from origin '<a href="https://app.roll20.net" rel="nofollow">https://app.roll20.net</a>' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. Steps to reproduce: Go to Conpendium. Search "drow". Open Drow Priestess. Scroll down to Melee __ Rapier. There should be a One action icon there.&nbsp; Settings: Google Chrome&nbsp;Version 80.0.3987.149 Windows 10 JS enabled No additional antivirus (Windows Defender) uBlock Origin (disabled), Reddit Enhancement Suite, Vue Dev Tools, Eye Dropper.&nbsp; Not working on Chrome: Working on Firefox: Console log: (index):12 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'nonce-hHeTdn2mE9kuvfU3' <a href="http://cdn.inspectlet.com" rel="nofollow">http://cdn.inspectlet.com</a> https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a> <a href="http://stun.l.google.com" rel="nofollow">http://stun.l.google.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-rBPYfAszOmE5vzhTF4Hz4hQly2JLl2uhN4tDJLmXbc4='), or a nonce ('nonce-...') is required to enable inline execution. (index):13 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'nonce-hHeTdn2mE9kuvfU3' <a href="http://cdn.inspectlet.com" rel="nofollow">http://cdn.inspectlet.com</a> https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a> <a href="http://stun.l.google.com" rel="nofollow">http://stun.l.google.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-/XHNKTzdVLpPBcMgsOl9LN6PEC5ufZbaLdoU14BWKr0='), or a nonce ('nonce-...') is required to enable inline execution. jquery.migrate.js:20 JQMIGRATE: Logging is active ?timestamp=1586102365&amp;disablewebgl=false&amp;forcelongpolling=false&amp;offsite=false&amp;fbdebug=false&amp;forcetouch=false:15 CAMPAIGN ID: 6101378 app.js?1585829787:552 70 app.js?1585829787:554 TOUCH SUPPORTED: false app.js?1585829787:554 USING WEBGL ACCELERATION... app.js?1585829787:554 WEBGL STARTUP SUCCESS app.js?1585829787:556 Custom Sheet Translation app.js?1585829787:571 Loading Custom character sheet. app.js?1585829787:571 Including compendium template css. tutorial_tips.js:7 tuts loaded (index):1 [DOM] Found 2 elements with non-unique id #color_value: (More info: <a href="https://goo.gl/9p2vKq" rel="nofollow">https://goo.gl/9p2vKq</a>) &lt;input type=​"text" size=​"8" id=​"color_value"&gt;​ &lt;input type=​"text" size=​"8" id=​"color_value"&gt;​ sheetsandboxworker.js?1586102367140:682 Starting up WEB WORKER app.js?1585829787:562 Final page load. app.js?1585829787:560 Auth'ed. app.js?1585829787:560 Go post auth! app.js?1585829787:560 initial setup app.js?1585829787:561 joining game... 8app.js?1585829787:558 Full load page! app.js?1585829787:560 We have 8 pages app.js?1585829787:559 Player -M2sJWX_M4PBjcQXocVc is offline... app.js?1585829787:559 Player -M3DDAub_bHL8t74ZtB4 is offline... app.js?1585829787:559 Player -M3SiycGjg-Mj2IKduLG is offline... app.js?1585829787:559 Player -M3XpILhZSW8mRopemuX is offline... app.js?1585829787:559 Player -M3Y2CCaFptidsjQtFDr is offline... app.js?1585829787:561 Deferred finish joining... app.js?1585829787:552 Firebase Online (index):1 [DOM] Found 9 elements with non-unique id #color_value: (More info: <a href="https://goo.gl/9p2vKq" rel="nofollow">https://goo.gl/9p2vKq</a>) &lt;input type=​"text" size=​"8" id=​"color_value"&gt;​ &lt;input type=​"text" size=​"8" id=​"color_value"&gt;​ &lt;input type=​"text" size=​"8" id=​"color_value"&gt;​ &lt;input type=​"text" size=​"8" id=​"color_value"&gt;​ &lt;input type=​"text" size=​"8" id=​"color_value"&gt;​ &lt;input type=​"text" size=​"8" id=​"color_value"&gt;​ &lt;input type=​"text" size=​"8" id=​"color_value"&gt;​ &lt;input type=​"text" size=​"8" id=​"color_value"&gt;​ &lt;input type=​"text" size=​"8" id=​"color_value"&gt;​ 60app.js?1585829787:570 Error while checking for roll total... app.js?1585829787:581 DOMException: Permission denied t.errorLog @ app.js?1585829787:581 (index):1 Access to image at '<a href="https://imgsrv.roll20.net/?src=/images/character.png&amp;cb=5" rel="nofollow">https://imgsrv.roll20.net/?src=/images/character.png&amp;cb=5</a>' from origin '<a href="https://app.roll20.net" rel="nofollow">https://app.roll20.net</a>' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. imgsrv.roll20.net/:1 Failed to load resource: net::ERR_FAILED app.js?1585829787:552 Error loading graphic, probably due to CORS. Trying once without CORS for /images/character.png (anonymous) @ app.js?1585829787:552 DevTools failed to parse SourceMap: <a href="https://app.roll20.net/js/d20/underscore-min.map" rel="nofollow">https://app.roll20.net/js/d20/underscore-min.map</a> (index):1 Invalid 'X-Frame-Options' header encountered when loading '<a href="https://app.roll20.net/compendium/pf2/Monsters%3ADrow%20Priestess?sharedCompendium=6101378#h-Drow%20Priestess" rel="nofollow">https://app.roll20.net/compendium/pf2/Monsters%3ADrow%20Priestess?sharedCompendium=6101378#h-Drow%20Priestess</a>': '<a href="https://app.roll20.net" rel="nofollow">https://app.roll20.net</a>' is not a recognized directive. The header will be ignored. v2.js?1582765325:57 JQMIGRATE: Migrate is installed with logging active, version 3.0.0 v2.js?1582765325:57 JQMIGRATE: jQuery.expr[":"] is now jQuery.expr.pseudos i @ v2.js?1582765325:57 get @ v2.js?1582765325:57 (anonymous) @ v2.js?1582765325:178 Sweetalert2.swal.sweetAlert.Swal.SweetAlert @ v2.js?1582765325:178 (anonymous) @ v2.js?1582765325:178 v2.js?1582765325:57 console.trace i @ v2.js?1582765325:57 get @ v2.js?1582765325:57 (anonymous) @ v2.js?1582765325:178 Sweetalert2.swal.sweetAlert.Swal.SweetAlert @ v2.js?1582765325:178 (anonymous) @ v2.js?1582765325:178 compendium.js?1568130237:650 t.fn.init [div#tableofcontents] /compendium/pf2/Monsters%3ADrow%20Priestess?sharedCompendium=6101378#h-Drow%20Priestess:1 Access to image at '<a href="https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png</a>' from origin '<a href="https://app.roll20.net" rel="nofollow">https://app.roll20.net</a>' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. v2.js?1582765325:50 GET <a href="https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/86669372/Pcb4lIrqUua7EyhBvSJzDw/med.png</a> net::ERR_FAILED M @ v2.js?1582765325:50 css @ v2.js?1582765325:51 Vt @ v2.js?1582765325:51 w @ v2.js?1582765325:50 show @ v2.js?1582765325:51 xt.fn.&lt;computed&gt; @ v2.js?1582765325:51 (anonymous) @ v2.js?1582765325:183 (anonymous) @ jquery-ui.1.11.2.min.js?1483835727:11 (anonymous) @ Monsters%3ADrow Priestess?sharedCompendium=6101378:1323 v2.js?1582765325:57 JQMIGRATE: jQuery.fn.removeAttr no longer sets boolean properties: required i @ v2.js?1582765325:57 (anonymous) @ v2.js?1582765325:57 each @ v2.js?1582765325:50 t.fn.removeAttr @ v2.js?1582765325:57 buildDom @ typeahead.js?1483835727:1652 Typeahead @ typeahead.js?1483835727:1458 attach @ typeahead.js?1483835727:1708 each @ v2.js?1582765325:50 each @ v2.js?1582765325:50 initialize @ typeahead.js?1483835727:1702 $.fn.typeahead @ typeahead.js?1483835727:1774 (anonymous) @ compendium.js?1568130237:233 h @ v2.js?1582765325:51 d @ v2.js?1582765325:51 setTimeout (async) (anonymous) @ v2.js?1582765325:51 u @ v2.js?1582765325:51 fireWith @ v2.js?1582765325:51 fire @ v2.js?1582765325:51 u @ v2.js?1582765325:51 fireWith @ v2.js?1582765325:51 ready @ v2.js?1582765325:51 d @ v2.js?1582765325:50 v2.js?1582765325:57 console.trace i @ v2.js?1582765325:57 (anonymous) @ v2.js?1582765325:57 each @ v2.js?1582765325:50 t.fn.removeAttr @ v2.js?1582765325:57 buildDom @ typeahead.js?1483835727:1652 Typeahead @ typeahead.js?1483835727:1458 attach @ typeahead.js?1483835727:1708 each @ v2.js?1582765325:50 each @ v2.js?1582765325:50 initialize @ typeahead.js?1483835727:1702 $.fn.typeahead @ typeahead.js?1483835727:1774 (anonymous) @ compendium.js?1568130237:233 h @ v2.js?1582765325:51 d @ v2.js?1582765325:51 setTimeout (async) (anonymous) @ v2.js?1582765325:51 u @ v2.js?1582765325:51 fireWith @ v2.js?1582765325:51 fire @ v2.js?1582765325:51 u @ v2.js?1582765325:51 fireWith @ v2.js?1582765325:51 ready @ v2.js?1582765325:51 d @ v2.js?1582765325:50
Confirmed same issue on MS Edge for what it's worth.
Hey Brett, thank you for the report, I was able to replicate this on my end and have created a task for Dev to tend to regarding this issue. Sorry for the trouble, but thank you for bringing it up all the same!