Skip to content

refactor(workbench): delete the unmounted ext-apps runtime App bridge - #845

Merged
ScriptedAlchemy merged 2 commits into
mainfrom
chore/extapps-bridge
Sep 25, 2026
Merged

ScriptedAlchemy merged 2 commits into
mainfrom
chore/extapps-bridge

Conversation

@ScriptedAlchemy

Copy link
Copy Markdown
Owner

Decision: delete, not wire

The Workbench's ext-apps runtime App bridge (packages/workbench/src/mcp/runtime-app-bridge.ts) has had no production caller since #629 (c9cc793) deleted the Runtime Playground, which was the only code that called createRuntimeAppBridgeFactory (via createWorkbenchRuntimeBridgeFactory → createBridgeFactory). #815 migrated the bridge to ext-apps 2.0, but nothing mounts it.

Evidence:

  • The two production mounts pass artifact props only: McpAppPreview in application/app-route-workspace.tsx and McpPage in advanced/advanced-page.tsx. McpAppPreview only imported the bridge's types, so the built Workbench never contained ext-apps code.
  • The live renderer is the artifact preview: a server-issued sandbox proxy iframe (McpAppPreviewFrame) driven by agent-bundle/src/web-host/browser/frame-relay.ts. It does not use the bridge or the Inspector-derived AppRenderer.
  • AppRenderer was reachable only through SecureAppRenderer in McpAppPreview's runtime branch. It was bundled but never executed.

So the bridge duplicates a path that has already been replaced. Nothing was missing from the live renderer, so there is nothing to wire.

What this deletes

  • runtime-app-bridge.ts and its test
  • The runtime overloads, state, and controller branch of McpAppPreview / McpAppPreviewController, plus the runtime inspection CSS
  • The runtime-bound mode of McpPage: McpPageRuntimeProps, the binding-admission helpers, the runtime JSX, and the Runtime-only registerPreviewClose prop
  • mcp-app-frame.tsx (SecureAppRenderer, McpAppFrame, applyMcpAppFramePolicy; none had a production caller), app-renderer.tsx, and APP-RENDERER-LICENSE, with the matching THIRD_PARTY_NOTICES paragraph, rsbuild copy entry, NOTICE bullet, README sentence, and security.mdx sentence (en and zh)
  • runtime-view-contracts.ts
  • @modelcontextprotocol/ext-apps from packages/workbench (examples/rsc-agent-runtime still depends on it)
  • The runtime-mode cases in the preview/page unit and browser tests. The frame-relay tests in mcp-app-frame.test.ts stay.
  • The topology script's tracked set, with the generated architecture block regenerated

There is no visible Workbench UI change: the removed branches never rendered in production. The browser suites below cover the live path at 1440×900.

Changeset

agent-bundle patch: dist/workbench stops shipping src/mcp/APP-RENDERER-LICENSE, and NOTICE / THIRD_PARTY_NOTICES drop the AppRenderer attribution.

Local gate (branch rebased on origin/main 6e836aa)

  • pnpm build ✅
  • pnpm typecheck ✅
  • pnpm lint ✅
  • pnpm test:unit ✅ (308 files; 4,431 passed, 6 skipped)
  • Integration (rstest.integration.config.ts, prebuilt): mcp-app-frame, mcp-app-preview-browser, mcp-page-app-browser, mcp-app-real.e2e, mcp-session-timeout.e2e, mcp-tasks.e2e, rsbuild-workbench, rsc-runtime-topology-script, dev-workbench ✅ (9 files, 66 tests)
  • Packed (scripts/run-packed-tests.mjs): dev-workbench-packaging, packed-small-plugin ✅ (6 tests)
  • pnpm docs:site:build ✅ (language parity OK, 0 broken links)

Review

change-risk-reviewer (Claude Opus 5.5) found no blockers. It checked that dropping the undefined guards and simplifying the props leaves the artifact path of McpAppPreviewController and McpPage unchanged, and that no deleted test covered live behavior.

  • Nit fixed: the changeset now ends with the PR number.
  • Nits not changed:
    • The APP-RENDERER-LICENSE fixture paths in dev-workbench.test.ts and workbench-asset-cache.test.ts stay. The tests create those files themselves to exercise generic notice serving, and dev-workbench.test.ts is being edited by an open legacy sweep.
    • The app-renderer entry in packed-small-plugin's filename regex stays; it is harmless.

Follow-ups (not in this PR)

  • Nothing in the Workbench calls the runtime methods on McpAppClient any more (createRuntime, operateRuntime, consent, currentDocumentPolicy, subscribeInvalidations, closeRuntime). As a result, the server's /api/runtime/apps routes (mcp-app-runtime-preview-service.ts) and the runtime source in mcp-session-controller / mcp-route-client look unused. Removing them changes the agent-bundle server surface.
  • packages/workbench/scripts/capture-runtime-playground.mjs and examples/rsc-agent-runtime/README.md still refer to the Runtime Playground that feat(workbench): application explorer — shell, Application tree, route workspace, one invocation API, page cuts (#600 PR 1) #629 removed.

The runtime App bridge (runtime-app-bridge.ts) lost its only production
caller when the Runtime Playground was removed in #629; since then nothing
constructed it and the built Workbench carried no ext-apps code. App route
previews render through the server-issued sandbox frame and the web-host
frame relay.

Delete the bridge and the runtime preview mode that only existed to host it:
the runtime overloads of McpAppPreview and McpPage, SecureAppRenderer and the
Inspector-derived AppRenderer (with its license and notice), and
runtime-view-contracts. Drop @modelcontextprotocol/ext-apps from the
Workbench.
@changeset-bot

changeset-bot Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0cfa95e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
agent-bundle Patch
create-agent-bundle Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-25T02:43:04.006122Z c51dcb4 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@ScriptedAlchemy
ScriptedAlchemy merged commit ff7421b into main Sep 25, 2026
3 checks passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c51dcb47f0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

"agent-bundle": patch
---

Remove the unused runtime MCP App renderer from the bundled Workbench. App previews keep rendering through the server-issued sandbox frame; the package no longer ships `dist/workbench/src/mcp/APP-RENDERER-LICENSE`, and `NOTICE` and `THIRD_PARTY_NOTICES` drop the MCP Inspector `AppRenderer` attribution.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Append the PR number to the changeset summary

The changeset summary ends without the required (#PR) suffix, so it does not satisfy the repository's release-note format and may fail changeset validation. Append the actual pull-request number to this line.

AGENTS.md reference: AGENTS.md:L124-L125

Useful? React with 👍 / 👎.

@github-actions github-actions Bot mentioned this pull request Sep 25, 2026
ScriptedAlchemy added a commit that referenced this pull request Sep 25, 2026
* refactor(dev)!: delete the callerless runtime App preview path

Since the Runtime Playground and the Workbench runtime App bridge were
deleted (#629, #845), nothing calls the runtime App lane. Remove it end to
end: the dev server's /api/runtime/apps and /api/runtime/mcp/sessions routes,
the runtime preview and binding services, the runtime client-surface proxy
and its session bindings, DevServerSession.openRuntimeClientSurface, the
runtime methods on the Workbench McpAppClient and McpRouteClient, the
runtime-bound McpSessionController mode and App attachment, and the
runtime.app.updated / runtime.hmr.client-* events with the Workbench's
unread HMR client counts. Delete the Runtime Playground capture script and
its README recipe.

* refactor(dev): keep Node-only sandbox code out of the browser contract graph

Move the MCP App sandbox and consent type declarations into a Node-free
mcp-app-sandbox-types.ts leaf and point every importer at it. The deleted
runtime preview service had been pulling @types/node into the browser-only
web-host program, which hid that contracts/mcp-apps.ts reached the Node
sandbox module. Also delete DevRuntimeController.emit, whose only callers
were the removed client-surface proxy and preview service, and drop the
deleted consent files from the topology test fixture.

* docs(changeset): reference #852
@ScriptedAlchemy
ScriptedAlchemy deleted the chore/extapps-bridge branch September 25, 2026 20:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant