Define a breaking-change process for Apps security and CSP behavior
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 30/100
- Issue type
- Documentation
- Clarity
- Needs clarification
- Activity status
- Quiet
- Tech stack
- wasm
- Domain
- documentation, security
Research direction
Review the related discussions in #378, #199, #605, and #667 to identify the breaking-change patterns and compatibility concerns they raise. Define a process covering host and server coordination, migration planning, compatibility windows, and versioning, with enough guidance for adoption without unexpected breakage.
Written by the indexing model from the issue text.
Description
Problem
Several active Apps discussions suggest broad-breaking changes (e.g., security-sensitive CSP issues), which would require coordination among several hosts and hundreds of apps.
Examples:
- #378 proposes Trusted Types metadata for code-evaluation use cases.
- #199 tracks
unsafe-eval/ Three.js behavior and the gap between strict spec CSP and permissive reference-host behavior. - #605 / #667 add explicit
wasm-unsafe-evalsupport for WebAssembly compilation.
The spec doesn't have a defined process for introducing breaking changes, which may require broader migration planning, host coordination, compatibility windows, or versioning.
Why this matters
The spec's ability to evolve is limited so long as we're unable to change the behavior in a responsible manner.
Desired Outcome
Define a process that allows hosts and servers to reasonably adopt spec changes without breaking.
- Dominant language
- TypeScript
- Stars
- 2.9k
- Forks
- 387
- Avg merge
- 3h 21m
- Merged PRs (30d)
- 6
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from modelcontextprotocol/ext-apps
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
modelcontextprotocol/ext-apps#767 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
modelcontextprotocol/ext-apps#742 · 1 comment ·
-
Difficulty 1/5 Under an hour Newbie friendliness 72/100
modelcontextprotocol/ext-apps#711 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
modelcontextprotocol/ext-apps#706 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
modelcontextprotocol/ext-apps#703 · 1 reaction ·
All issues in modelcontextprotocol/ext-apps
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
ontola/atomic-server#1625 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
melgarafael/DeskcommCRM#1451 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100
-
bug via-triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
bot:ai-assisted component:compact-js status:untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
midnightntwrk/midnight-sdk#403 ·