Guide for IT staff
Matematik i Måneby runs in the browser with no installation and no login. When it does not run on school computers, the cause is almost always a central setting. The game's error screen shows a line starting with For IT: and a link to the matching section below.
In short, maaneby.dk needs to be allowed:
- to use JavaScript JIT in Chrome:
JavaScriptJitAllowedForSites=[*.]maaneby.dk(WebAssembly) - to download every file under
https://maaneby.dk/unchanged (web filter) - to draw with WebGL2, so hardware acceleration must be on (WebGL)
- to store local data, if games are to be saved (storage)
WebAssembly is switched off
The error screen says WebAssembly: slået fra (switched off). The game's engine is
WebAssembly, and Chrome switches WebAssembly off when JavaScript JIT is blocked. That is what
the policy DefaultJavaScriptJitSetting set to 2 (Do not allow any site to run
JavaScript JIT) does, and some school authorities use it as hardening. Edge and phones
usually work, because the policy is only set for Chrome.
The fix is an exception for the site, so the rest of the hardening stays in place:
JavaScriptJitAllowedForSites with the value [*.]maaneby.dk. Google
enforces the exception per site, so exactly this form covers both maaneby.dk and
www.maaneby.dk.
Google Admin console (Chromebooks and managed Chrome)
- Sign in to the Google Admin console with an administrator account.
- Go to Menu > Devices > Chrome > Settings. The User & browser settings page opens.
- Select the organizational unit with the pupils' accounts at the side.
- Find JavaScript JIT in the Content group (or search for it).
- Leave the default as it is, and add
[*.]maaneby.dkto the list of URLs allowed to run JavaScript JIT. - Click Save. According to Google it usually takes effect within minutes, but can take up to 24 hours.
Windows: Group Policy
- Install Chrome's ADMX templates (from the Google Chrome Bundle) if they are not there already.
- Open Computer Configuration > Administrative Templates > Google > Google Chrome > Content settings.
- Open Allow JavaScript to use JIT on these sites, choose Enabled, click Show, and add
[*.]maaneby.dk.
Intune
Import Chrome's ADMX files (first google.admx, then chrome.admx) under
Devices > Configuration profiles > Import ADMX, create a profile of type
Templates > Imported Administrative templates, and set the same setting as
above. Google describes the steps in detail (see the sources at the bottom).
Registry
The policy is a list. Each value is a string (REG_SZ) named with a sequence number:
HKLM\SOFTWARE\Policies\Google\Chrome\JavaScriptJitAllowedForSites
1 REG_SZ [*.]maaneby.dk
As a command (use the next free number if 1 is already taken):
reg add "HKLM\SOFTWARE\Policies\Google\Chrome\JavaScriptJitAllowedForSites" /v 1 /t REG_SZ /d "[*.]maaneby.dk" /f
Check that it works
Open chrome://policy on a pupil's machine, click Reload policies, and check
that JavaScriptJitAllowedForSites is listed with [*.]maaneby.dk. Then
open maaneby.dk/en/spil/ in a new tab.
Edge
Edge has the same two policies, in case Edge is locked down too:
JavaScriptJitAllowedForSites under Administrative Templates > Microsoft Edge >
Content settings, in the registry under
HKLM\SOFTWARE\Policies\Microsoft\Edge\JavaScriptJitAllowedForSites. If you use Edge's
enhanced security mode (EnhanceSecurityMode), also add maaneby.dk to
EnhanceSecurityModeBypassListDomains.
A web filter blocks the game's files
The error screen names a file, for example main.dcr: HTTP 403,
(blokeret eller offline) (blocked or offline) or ikke en film (not a
movie). The last one means the filter answered with a page of its own instead of the file.
Allow:
| Address | Contents | Content-Type |
|---|---|---|
https://maaneby.dk/ | The whole site. www.maaneby.dk only redirects here. | |
/game/** | The game itself, which /spil/ shows in an iframe | |
/game/matematik-i-maaneby/*.dcr | The game's 19 Director movies, up to 22 MB each | application/octet-stream |
/game/polyfill-dist/*.wasm | The engine (7.7 MB) and four small extensions | application/wasm |
/game/polyfill-dist/*.js, /game/host/*.js, /game/fixes/*.js | Scripts | application/javascript |
/game/sw.js | Service worker that keeps the movies for next time (see storage) | application/javascript |
The files must arrive unchanged: not replaced by a warning page, not cut short, and with the
type application/wasm kept on .wasm. If a proxy scans large files, the
first movies can take a long time. The game loads nothing from other addresses. The browser
may send Cloudflare's own network error reports to a.nel.cloudflare.com; you do not
need to allow those.
WebGL2 or hardware acceleration is switched off
The error screen says WebGL2: .... The game is drawn with WebGL2. Without it, it
can only run very slowly, and some screens are drawn wrong. Check:
-
HardwareAccelerationModeEnabledmust not be set to false (Windows, Mac, Linux). It needs a browser restart. -
Disable3DAPIsmust not be set to true. In the Admin console it is called 3D content, in the Content group. -
Old graphics drivers can make Chrome switch WebGL off by itself.
chrome://gpushows why.
Local storage or the service worker is blocked
The game saves in the browser on each computer (localStorage), and a service worker keeps the
downloaded movies in the browser's cache so they are not downloaded again. If local data is
blocked, for example with DefaultCookiesSetting = 2 (Do not allow any site to set
local data), the game still starts, but it cannot be saved for next time, and the movies
are downloaded again every time. Allow local data for the site with
CookiesAllowedForUrls = [*.]maaneby.dk (in the Admin console:
Cookies in the Content group, Allow cookies for URL patterns).
If browser data is cleared at sign-out, saved games go with it.
The game stalled while downloading
The error screen says tidsgrænse: ... (time limit). The title screen did not
appear within a minute, and nothing was downloading. The usual cause is a filter or proxy
holding the files back (see web filter), or a heavily loaded network (see
bandwidth).
Bandwidth
- About 10 MB is downloaded before the first click, 7.7 MB of it the engine.
- A pupil downloads about 70 MB from the start up to and including the first task. Each new task is a movie of 6 to 22 MB.
- The files stay in the browser's cache afterwards, so the next time on the same computer is faster.
Start the game a few minutes before the lesson, and not on 25 machines in the same second. 25 pupils at once is around 1.75 GB over the school's line.
Privacy and security
- Free, with no login and no ads.
- The site collects no personal data and has no tracking or analytics.
- Stored locally in the browser: only the game's own saved games and settings (language), plus the downloaded movies in the browser's cache. Nothing is sent back to the server.
- The site is static and hosted by Cloudflare (Cloudflare Pages).
- The game is the original from 2005 and is available with permission from Bitfrost Interactive (about the project).
Contact
Questions from IT: write to [email protected]. Please include the For IT line from the error screen; a photo is fine.
Sources
- JavaScriptJitAllowedForSites and DefaultJavaScriptJitSetting (Chrome Enterprise)
- Set Chrome policies for users or browsers (Google, Admin console)
- Set Chrome browser policies on managed PCs (Google, Group Policy)
- Manage Chrome browser with Microsoft's Intune Import Administrative templates (Google)
- HardwareAccelerationModeEnabled, Disable3DAPIs, DefaultCookiesSetting, CookiesAllowedForUrls (Chrome Enterprise)
- JavaScriptJitAllowedForSites and EnhanceSecurityModeBypassListDomains (Microsoft Edge)