# Building ClickClue assets

Readable browser sources are included in `src/`. The admin scripts and styles in `assets/` are also readable. This package includes its own asset build script and dependency lockfile. The replay engine uses rrweb 2.1.4 (MIT); see THIRD-PARTY-LICENSES.txt.

On a development machine with Node.js 22, from this plugin directory run:

```
npm ci --prefix build
npm run build --prefix build
```

Do not install development dependencies on the production WordPress server. The build uses esbuild 0.28.2, IIFE output, ES2020 target and retained legal comments. All application imports resolve within this package; the build directory pins external libraries.

The build writes the replay document from `src/player-shell.html`, the bundled player and the replay/player styles. `src/player-document.mjs` calculates its exact Content Security Policy script hash. Do not hand-edit the generated player document.

The controller mounts the replay document at an opaque-origin data URL. Recorded pages remain in an inner frame with scripts disabled. Recording events are not embedded in the data URL or sent with the static player request.
