Pre-built code blocks

Game saves, audio and a shared backend

Game infrastructure — saves that migrate, audio with no assets, a maze, and an anonymous shared backend

For when the answer to “It is a game — saves that survive updates, sound, and a shared no-accounts backend” is yes.

store-kit solves 'my data must survive a reload'; this block is the layer a GAME needs on top of that: a save whose shape can change between releases without wiping what the player earned (schemaVersion step-migration), sound that ships…

A game cartridge passing unchanged through an arch that is itself changing shape, beside a speaker cone throwing rounded ripples and a short row of upright bars

Skip the rebuild

You do not write this one. It arrives in your project as ordinary source you can read, change and keep, with its audit record and its caveats beside it.

  1. Download the Playground. It is free and runs on your own machine.
  2. Start a new app and tick “It is a game — saves that survive updates, sound, and a shared no-accounts backend”.
  3. This block is written in, along with anything else you ticked.

Download the Playground See the other blocks

The mistake it removes

The kv-service is a PUBLIC, UNAUTHENTICATED endpoint by design — that is what 'no accounts' costs. Its defenses are real but narrow: claim tokens stop overwrites, per-IP fixed-window limits slow floods, the entry ceiling caps backend quota drain, and the injected validator is the only thing standing between you and a generic blob dump — write a strict one. What it cannot do: per-IP limits are only as good as x-forwarded-for from YOUR proxy (a caller who controls that header picks their own bucket), tokens are bearer secrets a device stores in localStorage, and nothing moderates the CONTENT of what players write — a shared store that renders player text needs its own escaping and its own moderation answer before it goes live.

What is already handled

Each of these was checked by running the code, not by reading it.

What the audit found

Named rather than summarized. The reasoning behind each one ships inside the block, so it travels with the code instead of living on a page you have to trust.

What you still have to do

A copied file cannot own your secrets, your host or your legal obligations. This is the part the block deliberately does not claim.

What lands in your project

node

  • node/gaming-kit.js
  • node/config.js
  • node/storage.js
  • node/kv-service.js
  • node/save.js
  • node/maze.js
  • node/audio.js
  • node/fx.js

Compiled JS (tsc, ES2022/NodeNext) from the TypeScript source — no build step needed by the consumer. Zero imports of anything: no packages, no node: builtins, no cross-file imports except the barrel's own relative re-exports. gaming-kit.js is the barrel (renamed from index.js: the scaffold flattens every node stack into server/blocks/ by basename, and challenge-kit's barrel already owns index.js there — a block-named barrel can never collide); take it or import a single module. audio.js and storage.js are browser-oriented but load and test in plain Node because their globals are injected, so they ship in this stack rather than pretending to be a second one.

react

  • react/index.js
  • react/modal.js
  • react/banner.js
  • react/hp-bar.js
  • react/wheel.js
  • react/odds.js
  • react/theme.js
  • react/use-pwa-install.js
  • react/use-tilt.js

JSX compiled to plain JS (react-jsx runtime), importing only `react` and `react/jsx-runtime`. Modal (focus trap, aria-modal, Escape), Banner, HpBar, a weighted prize Wheel driven by the pure odds table in odds.js, the PWA install-prompt hook, and the device-tilt input hook. The files land side by side so the barrel's relative imports resolve after install.

Needs react >=18 from npm.

What you supply

Licensed MIT. It is a starting point, not a finished product.

Get it

Download the Playground See the other blocks

Nothing here is locked. The files are yours, in your folder, under a permissive license.

Questions

Is Game saves, audio and a shared backend audited?
It was audited on 2026-08-24, and the verdict was not a clean pass.
What do I still have to do myself?
Terminate the kv-service behind a proxy that OVERWRITES x-forwarded-for (Cloudflare, a load balancer, your platform's edge), and stand up the Upstash-style Redis backend the rate limiter counts in. Exposed directly, a caller who sets the header picks their own bucket and the per-IP limits are advisory.
How do I get this code?
Download the Playground, start a new app, and tick “It is a game — saves that survive updates, sound, and a shared no-accounts backend”. The block is written into your project as ordinary source you can read and edit.

All pre-built code blocks · Learn to build from zero · The coding guide