This is the code I obtain when I refresh the page, on Chrome : Calling Element.createShadowRoot() for an element which already hosts a shadow root is deprecated. See <a href="https://www.chromestatus.com/features/4668884095336448" rel="nofollow">https://www.chromestatus.com/features/4668884095336448</a> for more details. init @ include.preload.js:465 (anonymous) @ include.preload.js:628 app.roll20.net/:12 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a> <a href="http://stun.l.google.com" rel="nofollow">http://stun.l.google.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-DsDCX1MysT9JAUf/tPJo9sNv2mKxAy0Xk2lECCS1cFo='), or a nonce ('nonce-...') is required to enable inline execution. app.roll20.net/:13 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a> <a href="http://stun.l.google.com" rel="nofollow">http://stun.l.google.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-g/RZo8vf07Pu8/gSqYdWwmd3NQYKzaVylxDWr2JAUf0='), or a nonce ('nonce-...') is required to enable inline execution. app.js?1481840798:31 70 app.js?1481840798:31 TOUCH SUPPORTED: false app.js?1481840798:31 USING WEBGL ACCELERATION... app.js?1481840798:31 WEBGL STARTUP SUCCESS app.js?1481840798:26 select app.js?1481840798:26 Switch mode to select app.js?1481840798:42 Initializing new dice engine with randomness... app.js?1481840798:42 Using random entropy app.js?1481840798:47 window resize app.js?1481840798:32 Final set zoom! app.js?1481840798:31 UPDATE GL SIZE! app.js?1481840798:32 Final set zoom! tutorial_tips.js:7 tuts loaded app.js?1481840798:38 Final page load. app.js?1481840798:37 Auth'ed. app.js?1481840798:37 Go post auth! app.js?1481840798:37 initial setup app.js?1481840798:35 T.r {attributes: Object, _escapedAttributes: Object, cid: "c0", changed: Object, _silent: Object…} app.js?1481840798:37 Got players value... app.js?1481840798:37 joining game... app.js?1481840798:35 Player -KZ76b4n0e8k9kVaMZ-L is offline... app.js?1481840798:36 Global Volume: 100=1 app.js?1481840798:35 Player -KZIc2gy0w1f-uwwHxyn is offline... app.js?1481840798:37 Deferred finish joining... app.js?1481840798:31 Firebase Online 16app.js?1481840798:35 Full load page! app.js?1481840798:37 We have 16 pages app.js?1481840798:37 handle page changes app.js?1481840798:37 false app.js?1481840798:38 Scan for new plays! app.js?1481840798:33 Do refresh link cache! app.js?1481840798:45 Refresh Journal List! app.js?1481840798:45 Search took 12ms app.js?1481840798:37 init active page! app.js?1481840798:35 activate page! app.js?1481840798:35 FULLY ACTIVATE VIEWS FOR PAGE. app.js?1481840798:35 Graphics: 0 app.js?1481840798:35 Paths: 0 app.js?1481840798:35 Reorder by ZORDER app.js?1481840798:35 Reorder by ZORDER