Hi Dan,
Please see the logs below obtained from the web browser console.
I get lots of similar messages complaining about security issues?
In the end, Atom seems to be looking the SWF file from a wrong
location.
Hope this could be of any help.
-----cut here---
Navigated to
https://mysite.com/index.php/fundo_xpto/multiFileUpload
modernizr.js:4 Refused to apply inline style because it violates the
following Content Security Policy directive: "default-src 'self'".
Either the 'unsafe-inline' keyword, a hash
('sha256-CwE3Bg0VYQOIdNAkbB/Btdkhul49qZuwgNCMPgNY5zw='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'style-src' was not explicitly set, so 'default-src' is used as a
fallback.
y @ modernizr.js:4
s.touch @ modernizr.js:4
(anonymous) @ modernizr.js:4
(anonymous) @ modernizr.js:4
modernizr.js:4 Refused to apply inline style because it violates the
following Content Security Policy directive: "default-src 'self'".
Either the 'unsafe-inline' keyword, a hash
('sha256-MZKTI0Eg1N13tshpFaVW65co/LeICXq4hyVx6GWVlK0='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'style-src' was not explicitly set, so 'default-src' is used as a
fallback.
y @ modernizr.js:4
s.csstransforms3d @ modernizr.js:4
(anonymous) @ modernizr.js:4
(anonymous) @ modernizr.js:4
modernizr.js:4 Refused to apply inline style because it violates the
following Content Security Policy directive: "default-src 'self'".
Either the 'unsafe-inline' keyword, a hash
('sha256-LpfmXS+4ZtL2uPRZgkoR29Ghbxcfime/CsD/4w5VujE='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'style-src' was not explicitly set, so 'default-src' is used as a
fallback.
y @ modernizr.js:4
s.fontface @ modernizr.js:4
(anonymous) @ modernizr.js:4
(anonymous) @ modernizr.js:4
modernizr.js:4 Refused to apply inline style because it violates the
following Content Security Policy directive: "default-src 'self'".
Either the 'unsafe-inline' keyword, a hash
('sha256-YJO/M9OgDKEBRKGqp4Zd07dzlagbB+qmKgThG52u/Mk='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'style-src' was not explicitly set, so 'default-src' is used as a
fallback.
y @ modernizr.js:4
s.generatedcontent @ modernizr.js:4
(anonymous) @ modernizr.js:4
(anonymous) @ modernizr.js:4
multiFileUpload:46 Refused to execute inline script because it
violates the following Content Security Policy directive:
"default-src 'self'". Either the 'unsafe-inline' keyword, a hash
('sha256-XQSCpycGlQ/TCkPBfFho8/VzX2Yd/ju09dEt6abX8M8='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'script-src' was not explicitly set, so 'default-src' is used as a
fallback.
multiFileUpload:62 Refused to execute inline script because it
violates the following Content Security Policy directive:
"default-src 'self'". Either the 'unsafe-inline' keyword, a hash
('sha256-TBKxViw4fmnOv1c+rrQJu0ERA6FKtbvt/9k6IJJpBso='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'script-src' was not explicitly set, so 'default-src' is used as a
fallback.
multiFileUpload:427 Refused to apply inline style because it
violates the following Content Security Policy directive:
"default-src 'self'". Either the 'unsafe-inline' keyword, a hash
('sha256-biLFinpqYMtWHmXfkA1BPeCY0/fNt46SAZ+BBk5YUog='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'style-src' was not explicitly set, so 'default-src' is used as a
fallback.
multiFileUpload:440 Refused to apply inline style because it
violates the following Content Security Policy directive:
"default-src 'self'". Either the 'unsafe-inline' keyword, a hash
('sha256-ZdHxw9eWtnxUb3mk6tBS+gIiVUPE3pGM470keHPDFlE='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'style-src' was not explicitly set, so 'default-src' is used as a
fallback.
multiFileUpload:479 Refused to apply inline style because it
violates the following Content Security Policy directive:
"default-src 'self'". Either the 'unsafe-inline' keyword, a hash
('sha256-q5rmgt0qnS6vusTX681CxP1llW8fGLSs67L4+dVXYgM='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'style-src' was not explicitly set, so 'default-src' is used as a
fallback.
multiFileUpload:481 Refused to apply inline style because it
violates the following Content Security Policy directive:
"default-src 'self'". Either the 'unsafe-inline' keyword, a hash
('sha256-U1dTjUY5CFSoYbVbko3PIYFvQ53kaUhoQlKi6MYm11s='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'style-src' was not explicitly set, so 'default-src' is used as a
fallback.
multiFileUpload:482 Refused to apply inline style because it
violates the following Content Security Policy directive:
"default-src 'self'". Either the 'unsafe-inline' keyword, a hash
('sha256-Xe4z8fPUKiEOmL6fVMXtbZo4ymd976D7yIGL4Wjv9eA='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'style-src' was not explicitly set, so 'default-src' is used as a
fallback.
multiFileUpload:1 Refused to load the image
'
https://www.gravatar.com/avatar/bf2e3bdd3d0478277c75300da929bbcf?s=25'
because it violates the following Content Security Policy directive:
"default-src 'self'". Note that 'img-src' was not explicitly set, so
'default-src' is used as a fallback.
multiFileUpload:503 Refused to execute inline script because it
violates the following Content Security Policy directive:
"default-src 'self'". Either the 'unsafe-inline' keyword, a hash
('sha256-qUo05uEWPhWHwns9zmJn+UUgsHQ+LU+b+eKaB7GB668='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'script-src' was not explicitly set, so 'default-src' is used as a
fallback.
uploader-min.js:8 Refused to apply inline style because it violates
the following Content Security Policy directive: "default-src
'self'". Either the 'unsafe-inline' keyword, a hash
('sha256-6wRdeNJzEHNIsDAMAdKbdVLWIqu8b6+Bs+xVNZqplQw='), or a nonce
('nonce-...') is required to enable inline execution. Note also that
'style-src' was not explicitly set, so 'default-src' is used as a
fallback.
write @ uploader-min.js:8
_embedSWF @ uploader-min.js:9
YAHOO.widget.FlashAdapter @ uploader-min.js:9
YAHOO.widget.Uploader @ uploader-min.js:9
attach @ multiFileUpload.js:9
(anonymous) @ drupal.js:56
each @ jquery.js:2
Drupal.attachBehaviors @ drupal.js:54
(anonymous) @ drupal.js:349
l @ jquery.js:2
fireWith @ jquery.js:2
ready @ jquery.js:2
A @ jquery.js:2
uploader.swf:1 GET
https://mysite.com/index.php/fundo_xpto/assets/uploader.swf 404 (Not
Found)
----