I used Roll20 on Wednesday with no issues. After the update, I have load times of multiple minutes to access the main page, the forums, & basically everything except my games. My games infinitely load & never start. It is happening on three different devices with three different operating systems. The only way any games load is when I switch my phone to data. There are no issues with any other browser-based applications or internet access for any of my other apps (Steam, etc). I have changed nothing in regards to security on my computers for several months. I've spent over an hour waiting for pages to load just to find a solution, so I would guess others are experiencing the same issue but don't have the time or patience to wait it out. There seem to be JQMIGRATE issues, but I don't know what that means.
Chrome & Firefox, both current
Windows 7, 10, Android, all current
Avast Antivirus, current but unchanged
Extensions disabled
"Issues" for Game failing to load:
Content Security Policy blocks inline execution of scripts and stylesheets
The Content Security Policy (CSP) prevents cross-site scripting attacks by blocking inline execution of scripts and style sheets.
To solve this, move all inline scripts (e.g. onclick=[JS code]) and styles into external files.
⚠️ Allowing inline execution comes at the risk of script injection via injection of HTML script elements. If you absolutely must, you can allow inline script and styles by:
adding unsafe-inline as a source to the CSP header
adding the hash or nonce of the inline script to your CSP header.
2 directives
Directive Element Source code Status
script-src-elem /editor/:5 blocked
script-src-elem /editor/:20 blocked
Learn more: Learn more: Content Security Policy - Inline Code
Console for Game failing to load:
Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'sha256-dm6tOb8rwEmENe5+ec26sQvlH6Xd1CBZ7IvtZ4kJ1og=' 'sha256-jlxVUPsj/qdPM120UwbjpC4Tw7dq+obb7SYUV+lSfrI=' 'nonce-TEla2S91wl2t89x3' http://cdn.inspectlet.com https://*.googlesyndication.com https://*.doubleclick.net https://partner.googleadservices.com https://www.googletagservices.com https://ssl.google-analytics.com https://www.google-analytics.com https://ajax.googleapis.com http://ajax.googleapis.com https://d3clqjduf2gvxg.cloudfront.net https://cdn.firebase.com https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com http://static.opentok.com http://www.google-analytics.com http://cdn.crowdin.com https://crowdin.com http://stun.l.google.com *.sentry-cdn.com". Either the 'unsafe-inline' keyword, a hash ('sha256-kH8OfsIWm/j2az5XQDZmvxH0faTd3NBwLZS7nTM5Oy4='), or a nonce ('nonce-...') is required to enable inline execution.
/editor/:20 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' 'sha256-dm6tOb8rwEmENe5+ec26sQvlH6Xd1CBZ7IvtZ4kJ1og=' 'sha256-jlxVUPsj/qdPM120UwbjpC4Tw7dq+obb7SYUV+lSfrI=' 'nonce-TEla2S91wl2t89x3' http://cdn.inspectlet.com https://*.googlesyndication.com https://*.doubleclick.net https://partner.googleadservices.com https://www.googletagservices.com https://ssl.google-analytics.com https://www.google-analytics.com https://ajax.googleapis.com http://ajax.googleapis.com https://d3clqjduf2gvxg.cloudfront.net https://cdn.firebase.com https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com http://static.opentok.com http://www.google-analytics.com http://cdn.crowdin.com https://crowdin.com http://stun.l.google.com *.sentry-cdn.com". Either the 'unsafe-inline' keyword, a hash ('sha256-pTNkp50U6tVf8FuQzTMh762+Nza6SP/j648+XWvdL+s='), or a nonce ('nonce-...') is required to enable inline execution.
jquery.migrate.js:20 JQMIGRATE: Logging is active
?timestamp=160287471…forcetouch=false:15 CAMPAIGN ID: 7903680
VM62:334 Logged in - checking Account GDPR status: true
/editor/setcampaign/7903680:1 GET https://app.roll20.net/editor/ net::ERR_HTTP2_PROTOCOL_ERROR 200