refactor(workbench): delete the unmounted ext-apps runtime App bridge - #845
Conversation
The runtime App bridge (runtime-app-bridge.ts) lost its only production caller when the Runtime Playground was removed in #629; since then nothing constructed it and the built Workbench carried no ext-apps code. App route previews render through the server-issued sandbox frame and the web-host frame relay. Delete the bridge and the runtime preview mode that only existed to host it: the runtime overloads of McpAppPreview and McpPage, SecureAppRenderer and the Inspector-derived AppRenderer (with its license and notice), and runtime-view-contracts. Drop @modelcontextprotocol/ext-apps from the Workbench.
🦋 Changeset detectedLatest commit: 0cfa95e The changes in this PR will be included in the next version bump. This PR includes changesets to release 2 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c51dcb47f0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "agent-bundle": patch | ||
| --- | ||
|
|
||
| Remove the unused runtime MCP App renderer from the bundled Workbench. App previews keep rendering through the server-issued sandbox frame; the package no longer ships `dist/workbench/src/mcp/APP-RENDERER-LICENSE`, and `NOTICE` and `THIRD_PARTY_NOTICES` drop the MCP Inspector `AppRenderer` attribution. |
There was a problem hiding this comment.
Append the PR number to the changeset summary
The changeset summary ends without the required (#PR) suffix, so it does not satisfy the repository's release-note format and may fail changeset validation. Append the actual pull-request number to this line.
AGENTS.md reference: AGENTS.md:L124-L125
Useful? React with 👍 / 👎.
* refactor(dev)!: delete the callerless runtime App preview path Since the Runtime Playground and the Workbench runtime App bridge were deleted (#629, #845), nothing calls the runtime App lane. Remove it end to end: the dev server's /api/runtime/apps and /api/runtime/mcp/sessions routes, the runtime preview and binding services, the runtime client-surface proxy and its session bindings, DevServerSession.openRuntimeClientSurface, the runtime methods on the Workbench McpAppClient and McpRouteClient, the runtime-bound McpSessionController mode and App attachment, and the runtime.app.updated / runtime.hmr.client-* events with the Workbench's unread HMR client counts. Delete the Runtime Playground capture script and its README recipe. * refactor(dev): keep Node-only sandbox code out of the browser contract graph Move the MCP App sandbox and consent type declarations into a Node-free mcp-app-sandbox-types.ts leaf and point every importer at it. The deleted runtime preview service had been pulling @types/node into the browser-only web-host program, which hid that contracts/mcp-apps.ts reached the Node sandbox module. Also delete DevRuntimeController.emit, whose only callers were the removed client-surface proxy and preview service, and drop the deleted consent files from the topology test fixture. * docs(changeset): reference #852
Decision: delete, not wire
The Workbench's ext-apps runtime App bridge (
packages/workbench/src/mcp/runtime-app-bridge.ts) has had no production caller since #629 (c9cc793) deleted the Runtime Playground, which was the only code that calledcreateRuntimeAppBridgeFactory(viacreateWorkbenchRuntimeBridgeFactory→createBridgeFactory). #815 migrated the bridge to ext-apps 2.0, but nothing mounts it.Evidence:
McpAppPreviewinapplication/app-route-workspace.tsxandMcpPageinadvanced/advanced-page.tsx.McpAppPreviewonly imported the bridge's types, so the built Workbench never contained ext-apps code.McpAppPreviewFrame) driven byagent-bundle/src/web-host/browser/frame-relay.ts. It does not use the bridge or the Inspector-derivedAppRenderer.AppRendererwas reachable only throughSecureAppRendererinMcpAppPreview's runtime branch. It was bundled but never executed.So the bridge duplicates a path that has already been replaced. Nothing was missing from the live renderer, so there is nothing to wire.
What this deletes
runtime-app-bridge.tsand its testMcpAppPreview/McpAppPreviewController, plus the runtime inspection CSSMcpPage:McpPageRuntimeProps, the binding-admission helpers, the runtime JSX, and the Runtime-onlyregisterPreviewClosepropmcp-app-frame.tsx(SecureAppRenderer,McpAppFrame,applyMcpAppFramePolicy; none had a production caller),app-renderer.tsx, andAPP-RENDERER-LICENSE, with the matching THIRD_PARTY_NOTICES paragraph, rsbuild copy entry, NOTICE bullet, README sentence, andsecurity.mdxsentence (en and zh)runtime-view-contracts.ts@modelcontextprotocol/ext-appsfrompackages/workbench(examples/rsc-agent-runtimestill depends on it)mcp-app-frame.test.tsstay.There is no visible Workbench UI change: the removed branches never rendered in production. The browser suites below cover the live path at 1440×900.
Changeset
agent-bundlepatch:dist/workbenchstops shippingsrc/mcp/APP-RENDERER-LICENSE, and NOTICE / THIRD_PARTY_NOTICES drop theAppRendererattribution.Local gate (branch rebased on origin/main 6e836aa)
pnpm build✅pnpm typecheck✅pnpm lint✅pnpm test:unit✅ (308 files; 4,431 passed, 6 skipped)rstest.integration.config.ts, prebuilt):mcp-app-frame,mcp-app-preview-browser,mcp-page-app-browser,mcp-app-real.e2e,mcp-session-timeout.e2e,mcp-tasks.e2e,rsbuild-workbench,rsc-runtime-topology-script,dev-workbench✅ (9 files, 66 tests)scripts/run-packed-tests.mjs):dev-workbench-packaging,packed-small-plugin✅ (6 tests)pnpm docs:site:build✅ (language parity OK, 0 broken links)Review
change-risk-reviewer(Claude Opus 5.5) found no blockers. It checked that dropping the undefined guards and simplifying the props leaves the artifact path ofMcpAppPreviewControllerandMcpPageunchanged, and that no deleted test covered live behavior.APP-RENDERER-LICENSEfixture paths indev-workbench.test.tsandworkbench-asset-cache.test.tsstay. The tests create those files themselves to exercise generic notice serving, anddev-workbench.test.tsis being edited by an open legacy sweep.app-rendererentry inpacked-small-plugin's filename regex stays; it is harmless.Follow-ups (not in this PR)
McpAppClientany more (createRuntime,operateRuntime, consent,currentDocumentPolicy,subscribeInvalidations,closeRuntime). As a result, the server's/api/runtime/appsroutes (mcp-app-runtime-preview-service.ts) and the runtime source inmcp-session-controller/mcp-route-clientlook unused. Removing them changes theagent-bundleserver surface.packages/workbench/scripts/capture-runtime-playground.mjsandexamples/rsc-agent-runtime/README.mdstill refer to the Runtime Playground that feat(workbench): application explorer — shell, Application tree, route workspace, one invocation API, page cuts (#600 PR 1) #629 removed.