Update: It's working now, after I installed adblocker, I had uninstalled it before. I wonder if it has something to do with VPN? I tried being off VPN before, and that didn't work... so I guess it's adblocker??? I also went off VPN, but I had already tried that. Update: it seems that chrome is blacklisting something, probably cloudfront.net. Why is it only not working for me? There is a script method for getting around that, but I don't know how to do that without specific instructions. Forticlient seems to be blocking Roll20 from loading. The problem URL is <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> I can turn off Forticlient or get another antivirus, but that's just not fair. You guys should fix it so that Forticlient works. :) I will submit a bug report with Forticlient, and I'll try to add an exception in it for cloudfront. Maybe this is more a Forticlient issue than a Roll20 issue... but still, this wasn't happening before. Happens with every game and on every browser. Thanks for your time. ^_^ ****UPDATE: I tried opening. Forticlient console by double-clicking on the mini icon thing. Click Web Security. Click the gear icon next to Protection by Site Category. Click Elevate (must have administrator privileges). Click Yes. Click Exclusions list. Click the plus sign in the upper right. Type cloudfront.net. Under Action, select Monitor. This should still stop any viruses or whatever on cloudfront while allowing you to go to the site. But it still doesn't work!!! I tried setting it to Allow. No worky. Forticlent does not report any violation!!! The only difference is now the chat sidebar is showing, but attempting to type anything yields a "No document!" error. ****UPDATE 2: I tried disabling both Forticlient and Malwarebytes anti-exploit (which didn't report any problems in its log) and no dice. Same story. ****UPDATE 3: Tried uninstalling adblocker, even though I only had it installed in chrome and roll20 doesnt work on other browsers either. No dice. Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net https://*.googlesyndication.com <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> https://*.googlesyndication.com <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> https://*.googlesyndication.com <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> https://*.googlesyndication.com https://*.firebaseio.com https://*.googlesyndication.com https://*.opentok.com https://*.googlesyndication.com <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-WTqfUNcoMkNfNepHaVc9eUa2AgSwaduLvyZgnsZKJzQ='), or a nonce ('nonce-...') is required to enable inline execution. app.roll20.net/:13 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net https://*.googlesyndication.com <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> https://*.googlesyndication.com <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> https://*.googlesyndication.com <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> https://*.googlesyndication.com https://*.firebaseio.com https://*.googlesyndication.com https://*.opentok.com https://*.googlesyndication.com <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-v19duySXMwXd3zUU660hZgcRTRW_BoLT6eLuziV0Xdk='), or a nonce ('nonce-...') is required to enable inline execution. <a href="https://d3clqjduf2gvxg.cloudfront.net/assets/fireb" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net/assets/fireb</a>... Failed to load resource: net::ERR_INSECURE_RESPONSE app.js:29 70 app.js:30 TOUCH SUPPORTED: false app.js:30 USING WEBGL ACCELERATION... app.js:30 WEBGL STARTUP SUCCESS app.js:29 Uncaught ReferenceError: Firebase is not defined <a href="https://d3clqjduf2gvxg.cloudfront.net/images/backg" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net/images/backg</a>... Failed to load resource: net::ERR_INSECURE_RESPONSE app.roll20.net/:37 Uncaught TypeError: d20ext.finalPageLoad is not a function Here is the revised thingy under Opera (previous one was under chrome): Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.firebaseio.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> ". Either the 'unsafe-inline' keyword, a hash ('sha256-8VAPqj4Qi9ziqxw3YycqIBDjtboJH5fk23qo-ZXaV9Q='), or a nonce ('nonce-...') is required to enable inline execution. app.roll20.net/:13 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.firebaseio.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> ". Either the 'unsafe-inline' keyword, a hash ('sha256-v19duySXMwXd3zUU660hZgcRTRW_BoLT6eLuziV0Xdk='), or a nonce ('nonce-...') is required to enable inline execution. app.js:29 70 app.js:30 TOUCH SUPPORTED: false app.js:25 select app.js:25 Switch mode to select app.js:40 Initializing new dice engine with randomness... app.js:40 Using random entropy app.js:43 Compiling sheet... app.js:43 Found rolltemplate: attack app.js:43 Found rolltemplate: damage app.js:43 Found rolltemplate: swDefault app.js:43 Found rolltemplate: swDefaultSkill app.js:43 Finding sheet rolls... app.js:44 window resize 2app.js:30 Final set zoom! tutorial_tips.js:7 tuts loaded app.roll20.net/:1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure image ' <a href="http://imgsrv.roll20.net/?src=www.rpgcircus.com/images/JumpCore1.png" rel="nofollow">http://imgsrv.roll20.net/?src=www.rpgcircus.com/images/JumpCore1.png</a> '. This content should also be served over HTTPS. app.js:36 Final page load. app.js:36 Scan for new plays! app.js:44 window resize 2app.js:30 Final set zoom! <a href="http://imgsrv.roll20.net/?src=www.rpgcircus.com/images/JumpCore1.png" rel="nofollow">http://imgsrv.roll20.net/?src=www.rpgcircus.com/images/JumpCore1.png</a> Failed to load resource: net::ERR_CONNECTION_TIMED_OUT firebase.1.0.15.js:54 WebSocket connection to 'wss://roll20-19.firebaseio.com/.ws?v=5' failed: WebSocket is closed before the connection is established.