fix(web): vendor the Macroquad browser loader

The page depended on the externally hosted miniquad bundle, which violates a
same-origin `script-src 'self'` policy and makes the game depend on a third
party at runtime. Vendor the current official loader alongside the web assets
and move the WASM `load` call into a local bootstrap script, preserving plugin
registration order without inline JavaScript.

Document the CSP requirement for WebAssembly compilation and same-origin
connections. The vendored bundle is the current response from the official
Macroquad loader URL and was syntax-checked before committing.

Test Plan:
- `just web-build` -- passed
- `node --check web/mq_js_bundle.js web/storage.js web/bootstrap.js` -- passed
- `prettier --check web/storage.js web/bootstrap.js` -- passed
- Browser smoke test with `script-src 'self' 'wasm-unsafe-eval'` and `connect-src 'self'` -- passed; 640x460 canvas and no CSP/script errors
- `git diff --cached --check` -- passed
This commit is contained in:
2026-08-29 17:12:43 +02:00
parent a81741b470
commit acb0c20b59
5 changed files with 18 additions and 7 deletions
+2
View File
@@ -10,6 +10,8 @@ and this project adheres to
### Fixed
- Bundle the official Macroquad browser loader and WASM bootstrap locally so a
CSP does not require inline JavaScript or code from `not-fl3.github.io`.
- Add the optional same-origin Axum/SQLite high-score service, browser
fetch/submit integration, and an nginx reverse-proxy example. Browser
settings retain their local-storage fallback, while the shared table is