1.9 KiB
Web Blender Modeler V1 Deployment Contract
The normative machine-readable contract is deployment-contract.json. A server is compatible only
when every response, including errors and SPA fallbacks, preserves these headers:
| Header | Required value |
|---|---|
Cross-Origin-Opener-Policy |
same-origin |
Cross-Origin-Embedder-Policy |
require-corp |
Cross-Origin-Resource-Policy |
same-origin |
Production uses HTTPS. Loopback development may use http://127.0.0.1; file:// is unsupported.
Runtime assets are same-origin. A reverse proxy must not strip the isolation, range, cache, MIME or
ETag headers.
Cache policy
/and/index.html:Cache-Control: no-cacheso a deployment is revalidated./engine-manifest.json:Cache-Control: no-cacheso engine identity is revalidated./assets/*:Cache-Control: public, max-age=31536000, immutable; Vite content hashes these names./vendor/blender/*:Cache-Control: no-cache; these stable URLs are verified by the engine manifest.- Other paths:
Cache-Control: no-cacheuntil a more specific content-addressed rule exists.
The server must use the MIME map in the JSON contract. In particular, WebAssembly is
application/wasm, JavaScript is text/javascript; charset=utf-8, and NanoVDB is
application/x-nanovdb.
Range and validators
.wasm, .blend and .nvdb accept a single bytes range. A valid range returns 206 with
Accept-Ranges, Content-Range, Content-Length and a strong content SHA-256 ETag. An invalid or
unsatisfied range returns 416. An If-Range mismatch ignores the range and returns the complete
resource with status 200; partial bytes from a different revision must never be combined.
Run node tools/web/check-deployment-contract.mjs for the static contract gate. Production HTTP
behavior is a separate M6 acceptance gate and must exercise an actual server before release.