Content releases and player state
| Owner | Owns | Boundary |
|---|---|---|
| Browser runtime | Isometric rendering, input, local animation, selectable dialogue, music | Animates approved routes; sends action intents |
| Engine service | Collision, encounter execution, rooms, membership, authoritative saves | Persists each accepted action before acknowledgement |
| Content pack | Maps, actors, artwork, soundtracks, dialogue and progression conditions | Validated JSON; no executable scripts |
| Workshop | Draft validation, scene preview, asset upload, immutable publication | Member validation; owner-only draft and publish APIs |
| Archive adapter | Authored story export and private source provenance | HTTPS export during authoring; original source material stays private |
One runtime, two games
The Unwritten Hour 1.0.0 adapts four existing chapters, keeping their dialogue, keepsakes, actor movement and progression gates. Signal Station 1.0.0 uses the same engine with unrelated maps and characters. Restoring its beacon sets a shared room flag; earning the maintenance badge remains individual progress.
The original Mage Archive world remains a separate running game. Its browser-local saves are not imported or overwritten. This first engine release provides a new journey, not a replacement of the sanctuary, its visual effects, or its live AI conversations.
State ownership
| State | Scope and persistence |
|---|---|
| Content | Immutable pack ID + semantic version + SHA-256. A room pins one engine-major-compatible release. |
| Room | Members, release, shared boolean flags. Up to eight explicitly invited members. |
| Player | Scene, approved route, inventory, individual flags, actor positions and dialogue checkpoints. Private to the authenticated member. |
| Presence | Peers visible in the same scene for 12 seconds after their last sync. No other player's inventory or dialogue is transmitted. |
| Page control | One browser controls a player. Another page must explicitly take control. Retired pages and stale sequences are rejected. |
Content vocabulary
Interacting starts authored dialogue or enters a conditionally unlocked exit. Dialogue beats and completion can move-actor, grant-item, or set-flag. Exit conditions reference player or room flags. A scene, character or chapter name has no special engine meaning. Unknown fields, unsupported effects, missing references and unreachable interactions fail validation.
Failure and recovery
| Failure | Visible outcome and recovery |
|---|---|
| Lost request or process restart | The client retains the action ID; the server retains its receipt. Retry cannot apply the action twice. The last confirmed save survives restart. |
| Disconnected engine | Five-second calls retry within a 30-second recovery window, then show a terminal error and Reconnect. Already approved routes may finish locally. |
| Rejected action | Concrete error; discard the rejected action or explicitly take control. No partial state is committed. |
| Archive or model unavailable | An established engine capability lasts 24 hours. Movement, authored dialogue and saves call only this service. New login requires archive membership verification. No model calls exist in this release. |
| Interrupted conversation | Leave or refresh retains its checkpoint. Only finishing grants completion effects. |
| Content rewrite | Publish a new version. Existing sessions remain on the old version; no automatic save migration. |
| Missing artwork or music | Artwork startup ends within 12 seconds; music within eight. Explicit error and retry/reload; no endless loading indicator. |
Deployment boundary
One writer owns an atomically replaced, fsynced state file under the engine service account. Restart deployment is supported; overlapping writer generations are not. Asset bytes are content-addressed and checked before delivery. Identity bootstrap trusts the explicitly configured archive AuthReturn registration and its membership API; engine action capabilities are scoped to this service and expire in 24 hours.
Current scope
Workshop publication is agent-driven through the authenticated API. Draft preview is a read-only rendering; playable sessions use published releases. Generative authoring, arbitrary mechanics extensions, branching dialogue, save migration and live private-context AI are not implemented. Add these through versioned contracts rather than executable content scripts.