Guide for IT staff

Matematik i Måneby runs in the browser with no installation and no login. When it does not run on school computers, the cause is almost always a central setting. The game's error screen shows a line starting with For IT: and a link to the matching section below.

In short, maaneby.dk needs to be allowed:

WebAssembly is switched off

The error screen says WebAssembly: slået fra (switched off). The game's engine is WebAssembly, and Chrome switches WebAssembly off when JavaScript JIT is blocked. That is what the policy DefaultJavaScriptJitSetting set to 2 (Do not allow any site to run JavaScript JIT) does, and some school authorities use it as hardening. Edge and phones usually work, because the policy is only set for Chrome.

The fix is an exception for the site, so the rest of the hardening stays in place: JavaScriptJitAllowedForSites with the value [*.]maaneby.dk. Google enforces the exception per site, so exactly this form covers both maaneby.dk and www.maaneby.dk.

Google Admin console (Chromebooks and managed Chrome)

  1. Sign in to the Google Admin console with an administrator account.
  2. Go to Menu > Devices > Chrome > Settings. The User & browser settings page opens.
  3. Select the organizational unit with the pupils' accounts at the side.
  4. Find JavaScript JIT in the Content group (or search for it).
  5. Leave the default as it is, and add [*.]maaneby.dk to the list of URLs allowed to run JavaScript JIT.
  6. Click Save. According to Google it usually takes effect within minutes, but can take up to 24 hours.

Windows: Group Policy

  1. Install Chrome's ADMX templates (from the Google Chrome Bundle) if they are not there already.
  2. Open Computer Configuration > Administrative Templates > Google > Google Chrome > Content settings.
  3. Open Allow JavaScript to use JIT on these sites, choose Enabled, click Show, and add [*.]maaneby.dk.

Intune

Import Chrome's ADMX files (first google.admx, then chrome.admx) under Devices > Configuration profiles > Import ADMX, create a profile of type Templates > Imported Administrative templates, and set the same setting as above. Google describes the steps in detail (see the sources at the bottom).

Registry

The policy is a list. Each value is a string (REG_SZ) named with a sequence number:

HKLM\SOFTWARE\Policies\Google\Chrome\JavaScriptJitAllowedForSites
    1    REG_SZ    [*.]maaneby.dk

As a command (use the next free number if 1 is already taken):

reg add "HKLM\SOFTWARE\Policies\Google\Chrome\JavaScriptJitAllowedForSites" /v 1 /t REG_SZ /d "[*.]maaneby.dk" /f

Check that it works

Open chrome://policy on a pupil's machine, click Reload policies, and check that JavaScriptJitAllowedForSites is listed with [*.]maaneby.dk. Then open maaneby.dk/en/spil/ in a new tab.

Edge

Edge has the same two policies, in case Edge is locked down too: JavaScriptJitAllowedForSites under Administrative Templates > Microsoft Edge > Content settings, in the registry under HKLM\SOFTWARE\Policies\Microsoft\Edge\JavaScriptJitAllowedForSites. If you use Edge's enhanced security mode (EnhanceSecurityMode), also add maaneby.dk to EnhanceSecurityModeBypassListDomains.

A web filter blocks the game's files

The error screen names a file, for example main.dcr: HTTP 403, (blokeret eller offline) (blocked or offline) or ikke en film (not a movie). The last one means the filter answered with a page of its own instead of the file. Allow:

AddressContentsContent-Type
https://maaneby.dk/The whole site. www.maaneby.dk only redirects here.
/game/**The game itself, which /spil/ shows in an iframe
/game/matematik-i-maaneby/*.dcrThe game's 19 Director movies, up to 22 MB eachapplication/octet-stream
/game/polyfill-dist/*.wasmThe engine (7.7 MB) and four small extensionsapplication/wasm
/game/polyfill-dist/*.js, /game/host/*.js, /game/fixes/*.jsScriptsapplication/javascript
/game/sw.jsService worker that keeps the movies for next time (see storage)application/javascript

The files must arrive unchanged: not replaced by a warning page, not cut short, and with the type application/wasm kept on .wasm. If a proxy scans large files, the first movies can take a long time. The game loads nothing from other addresses. The browser may send Cloudflare's own network error reports to a.nel.cloudflare.com; you do not need to allow those.

WebGL2 or hardware acceleration is switched off

The error screen says WebGL2: .... The game is drawn with WebGL2. Without it, it can only run very slowly, and some screens are drawn wrong. Check:

Local storage or the service worker is blocked

The game saves in the browser on each computer (localStorage), and a service worker keeps the downloaded movies in the browser's cache so they are not downloaded again. If local data is blocked, for example with DefaultCookiesSetting = 2 (Do not allow any site to set local data), the game still starts, but it cannot be saved for next time, and the movies are downloaded again every time. Allow local data for the site with CookiesAllowedForUrls = [*.]maaneby.dk (in the Admin console: Cookies in the Content group, Allow cookies for URL patterns). If browser data is cleared at sign-out, saved games go with it.

The game stalled while downloading

The error screen says tidsgrænse: ... (time limit). The title screen did not appear within a minute, and nothing was downloading. The usual cause is a filter or proxy holding the files back (see web filter), or a heavily loaded network (see bandwidth).

Bandwidth

Start the game a few minutes before the lesson, and not on 25 machines in the same second. 25 pupils at once is around 1.75 GB over the school's line.

Privacy and security

Contact

Questions from IT: write to [email protected]. Please include the For IT line from the error screen; a photo is fine.

Sources