Roll20 uses cookies to improve your experience on our site. Cookies enable you to enjoy certain features, social sharing functionality, and tailor message and display ads to your interests on our site and others. They also help us understand how our site is being used. By continuing to use our site, you consent to our use of cookies. Update your cookie preferences .
×

Placing cards throws CORS errors

I'm using chrome 87.0.4280.141, which I believe is the latest, on windows 10, fully updated as of now. I have adblock extension installed but disabled it to see if it changes anything. Also malwarebytes, also disabled for testing purposes. I have cleared my cache. My players have the same issues though I don't know their setups. The steps to reproduce this are to load a game, show the deck, flip a card onto the top, and attempt to place a card onto the map. The results are very inconsistent. Sometimes it will place the card, sometimes the card will just vanish. I'd say about 50% chance of either. The error log gets very chatty when a card "disappears" though The following is the console log after: (1) clicking the deck to successfully draw a card, (2) attempting to drag the card onto the map which fails: 15Mixed Content: The page at '&lt;URL&gt;' was loaded over HTTPS, but requested an insecure element '&lt;URL&gt;'. This request was automatically upgraded to HTTPS, For more information see &lt;URL&gt; (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1478/thumb.png?1335737811" rel="nofollow">http://files.d20.io/images/1478/thumb.png?1335737811</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1478/thumb.png?1335737811" rel="nofollow">http://files.d20.io/images/1478/thumb.png?1335737811</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1478/thumb.png?1335737811" rel="nofollow">http://files.d20.io/images/1478/thumb.png?1335737811</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1478/thumb.png?1335737811" rel="nofollow">http://files.d20.io/images/1478/thumb.png?1335737811</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1478/thumb.png?13357378115" rel="nofollow">http://files.d20.io/images/1478/thumb.png?13357378115</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure element '<a href="http://files.d20.io/images/1478/thumb.png?13357378111610305307541" rel="nofollow">http://files.d20.io/images/1478/thumb.png?13357378111610305307541</a>'. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Access to image at '<a href="https://files.d20.io/images/1478/thumb.png?13357378115" rel="nofollow">https://files.d20.io/images/1478/thumb.png?13357378115</a>' from origin '<a href="https://app.roll20.net" rel="nofollow">https://app.roll20.net</a>' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. files.d20.io/images/1478/thumb.png?13357378115:1 Failed to load resource: net::ERR_FAILED app.js?1609865416:585 Error loading graphic, probably due to CORS. Trying once without CORS for <a href="http://files.d20.io/images/1478/thumb.png?1335737811" rel="nofollow">http://files.d20.io/images/1478/thumb.png?1335737811</a> (anonymous) @ app.js?1609865416:585 nrWrapper @ (index):424 (index):1 Access to image at '<a href="https://files.d20.io/images/1478/thumb.png?13357378111610305307541" rel="nofollow">https://files.d20.io/images/1478/thumb.png?13357378111610305307541</a>' from origin '<a href="https://app.roll20.net" rel="nofollow">https://app.roll20.net</a>' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. files.d20.io/images/1478/thumb.png?13357378111610305307541:1 Failed to load resource: net::ERR_FAILED app.js?1609865416:585 Second load attempt failed for <a href="http://files.d20.io/images/1478/thumb.png?13357378111610305307541" rel="nofollow">http://files.d20.io/images/1478/thumb.png?13357378111610305307541</a> l @ app.js?1609865416:585 nrWrapper @ (index):424 DevTools failed to load SourceMap: Could not load content for <a href="https://app.roll20.net/js/d20/underscore-min.map" rel="nofollow">https://app.roll20.net/js/d20/underscore-min.map</a>: Fetch through target failed: Target not supported; Fallback: HTTP error: status code 404, net::ERR_HTTP_RESPONSE_CODE_FAILURE
1610305589

Edited 1610305633
Here's the console log when a card works: 14Mixed Content: The page at '&lt;URL&gt;' was loaded over HTTPS, but requested an insecure element '&lt;URL&gt;'. This request was automatically upgraded to HTTPS, For more information see &lt;URL&gt; (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1458/thumb.png?1335737641" rel="nofollow">http://files.d20.io/images/1458/thumb.png?1335737641</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1458/thumb.png?1335737641" rel="nofollow">http://files.d20.io/images/1458/thumb.png?1335737641</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1458/thumb.png?1335737641" rel="nofollow">http://files.d20.io/images/1458/thumb.png?1335737641</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1458/thumb.png?1335737641" rel="nofollow">http://files.d20.io/images/1458/thumb.png?1335737641</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1433/med.png?1335737429" rel="nofollow">http://files.d20.io/images/1433/med.png?1335737429</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a> (index):1 Mixed Content: The page at ' <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> ' was loaded over HTTPS, but requested an insecure element ' <a href="http://files.d20.io/images/1458/thumb.png?13357376415" rel="nofollow">http://files.d20.io/images/1458/thumb.png?13357376415</a> '. This request was automatically upgraded to HTTPS, For more information see <a href="https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html" rel="nofollow">https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html</a>
same thing is happening to me