The page depended on the externally hosted miniquad bundle, which violates a same-origin `script-src 'self'` policy and makes the game depend on a third party at runtime. Vendor the current official loader alongside the web assets and move the WASM `load` call into a local bootstrap script, preserving plugin registration order without inline JavaScript. Document the CSP requirement for WebAssembly compilation and same-origin connections. The vendored bundle is the current response from the official Macroquad loader URL and was syntax-checked before committing. Test Plan: - `just web-build` -- passed - `node --check web/mq_js_bundle.js web/storage.js web/bootstrap.js` -- passed - `prettier --check web/storage.js web/bootstrap.js` -- passed - Browser smoke test with `script-src 'self' 'wasm-unsafe-eval'` and `connect-src 'self'` -- passed; 640x460 canvas and no CSP/script errors - `git diff --cached --check` -- passed
TDK Pinball Machine web build
Build and serve the browser version from this directory with:
just web-serve
The game is compiled for wasm32-unknown-unknown and loaded into a fixed
640x460 canvas centered on the black page by index.html. Browser settings and
a fallback copy of the high-score table are saved in localStorage; native
builds continue to use their normal per-user save file.
The page includes the official Macroquad browser loader locally. The WASM
bootstrap is local as well, so the page does not require inline or third-party
JavaScript. The web page must be served over HTTP rather than opened directly
from a file: URL.
For a strict Content Security Policy, allow script-src 'self' 'wasm-unsafe-eval' for the browser's WebAssembly compilation and
connect-src 'self' for the local WASM and optional high-score API requests.
When the same-origin /api/highscores endpoint is available, the browser loads
and submits the shared top-ten table there. The small Axum service and an nginx
proxy example are in highscore-server.