
GravFlip Runner
Vanilla-JS anti-gravity platformer with 5-layer anti-cheat
Overview
GravFlip Runner is a fast-paced, neon-infused anti-gravity platformer built entirely from scratch, without any heavy frameworks. Instead of jumping, the player flips gravity to move between floors and ceilings, dodging hazards and collecting stars in an ever-accelerating deep-space environment. It's built as a fully production-ready browser game — high-performance rendering, procedural audio, offline play, and a real competitive leaderboard.
Technical Architecture & Specifications
Key Features & Implementation Highlights
- Four distinct game modes: Classic (endless survival), Mirror (simultaneous split-screen dual control), Blitz (relentless speed-ramp mode), and Campaign (5-world story mode)
- Five handcrafted campaign worlds: Neon City, Asteroid Belt, Solar Flare, The Singularity, and Crimson Void
- Dynamic visual themes transitioning between Deep Space, Neon Grid, Crimson Void, and Aurora
- Multiple hazard types: Laser Gates, Crushers, Phantom Blocks, and rotating Saw Blades
- Global leaderboard backed by Vercel KV Redis
- 5-layer server-side anti-cheat engine: HMAC SHA-256 token signing, physics-plausibility checks, frame-rate correlation, speed validation, and session banning
- Mobile-optimized with touch controls, blocked pinch-zoom, and iOS bounce-scroll prevention
Challenges & Tradeoffs
Building a competitive leaderboard for a browser game with no user accounts required a multi-layered anti-cheat approach. The 5-layer validation engine (HMAC signing, physics plausibility, frame-rate correlation, speed curve validation, and session banning) was necessary because client-side game state is inherently untrustworthy — any score submitted from the browser could be forged. Each validation layer catches a different class of cheating: HMAC prevents payload tampering, physics checks reject mathematically impossible scores, and frame-rate correlation catches automated scripts. The tradeoff is added server-side compute cost on every score submission and the risk of false positives (legitimate edge-case scores being rejected), but for a public leaderboard, accepting fake scores would undermine the entire competitive feature.