Here is my Chrome report: Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-1M8HTwv/cax6LG+u7p/qOTAoCSy0TomR4MdstgYdQ/c='), or a nonce ('nonce-...') is required to enable inline execution. app.roll20.net/:13 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-0e7Q3QqVn8f0h38oogzHudH+MBBdX9InX4bX658dij4='), or a nonce ('nonce-...') is required to enable inline execution. <a href="https://www.google-analytics.com/analytics.js" rel="nofollow">https://www.google-analytics.com/analytics.js</a> Failed to load resource: net::ERR_BLOCKED_BY_CLIENT app.js?1471269177:29 70 app.js?1471269177:30 TOUCH SUPPORTED: false app.js?1471269177:30 USING WEBGL ACCELERATION... app.js?1471269177:30 WEBGL STARTUP SUCCESS app.js?1471269177:32 Custom Sheet Translation app.js?1471269177:25 select app.js?1471269177:25 Switch mode to select app.js?1471269177:41 Initializing new dice engine with randomness... app.js?1471269177:41 Using random entropy app.js?1471269177:44 Compiling sheet... app.js?1471269177:44 Found rolltemplate: simple app.js?1471269177:44 Found rolltemplate: atk app.js?1471269177:44 Found rolltemplate: dmg app.js?1471269177:44 Found rolltemplate: atkdmg app.js?1471269177:44 Found rolltemplate: desc app.js?1471269177:44 Found rolltemplate: spell app.js?1471269177:44 Found rolltemplate: npc app.js?1471269177:44 Found rolltemplate: npcatk app.js?1471269177:44 Found rolltemplate: npcdmg app.js?1471269177:44 Found rolltemplate: npcaction app.js?1471269177:44 Found webworker script app.js?1471269177:44 Finding sheet rolls... app.js?1471269177:45 window resize app.js?1471269177:30 Final set zoom! app.js?1471269177:30 UPDATE GL SIZE! app.js?1471269177:30 Final set zoom! tutorial_tips.js:7 tuts loaded app.roll20.net/:1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png</a>'. This content should also be served over HTTPS. app.roll20.net/:1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/3OxOqmb.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/3OxOqmb.png</a>'. This content should also be served over HTTPS. 3app.roll20.net/:1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png</a>'. This content should also be served over HTTPS. app.roll20.net/:1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/py5B0cm.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/py5B0cm.png</a>'. This content should also be served over HTTPS. app.roll20.net/:1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/LoT21n1.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/LoT21n1.png</a>'. This content should also be served over HTTPS. sheetsandboxworker.js?20160628:226 Starting up WEB WORKER app.js?1471269177:36 Final page load. app.js?1471269177:36 Auth'ed. app.js?1471269177:36 Go post auth! app.js?1471269177:36 initial setup app.js?1471269177:34 T.r app.js?1471269177:36 Got players value... app.js?1471269177:36 joining game... 5app.js?1471269177:33 Full load page! app.js?1471269177:36 We have 5 pages app.js?1471269177:34 Global Volume: 100=1 app.js?1471269177:34 Player -KPiybrgzsZ40Sw8cP0e is offline... app.js?1471269177:36 Deferred finish joining... app.js?1471269177:29 Firebase Online app.js?1471269177:36 handle page changes app.js?1471269177:36 false app.js?1471269177:32 Do refresh link cache! app.js?1471269177:43 Refresh Journal List! app.js?1471269177:43 Search took 11ms app.js?1471269177:36 Scan for new plays! app.js?1471269177:36 init active page! app.js?1471269177:33 activate page! app.js?1471269177:33 FULLY ACTIVATE VIEWS FOR PAGE. app.js?1471269177:33 Graphics: 0 app.js?1471269177:33 Paths: 0 app.js?1471269177:33 Reorder by ZORDER app.js?1471269177:43 initiatlizing video chat app.js?1471269177:43 Connecting to WebRTC app.js?1471269177:43 Connected to session app.js?1471269177:43 Someone just connected. app.js?1471269177:43 It's us? app.js?1471269177:43 Someone just connected. app.js?1471269177:43 It's us? app.js?1471269177:45 window resize app.js?1471269177:30 Final set zoom! app.js?1471269177:30 UPDATE GL SIZE! app.js?1471269177:30 Final set zoom!