Repository navigation
Conversation
Permission keys are the Permission Policy feature names. clipboardWrite stays as a legacy alias and is deprecated in its favor.
Extend McpUiResourcePermissions with fullscreen, picture-in-picture, autoplay and encrypted-media.
Add a string index signature to McpUiResourcePermissions so views can request features without a named key, using the feature name verbatim.
The example declares fullscreen, picture-in-picture, autoplay and encrypted-media; the native video controls show the first two taking effect in basic-host.
jmsn
marked this pull request as ready for review
October 6, 2026 16:19
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Make UI resource permissions open-ended and add named permissions
fullscreen,picture-in-picture,autoplayandencrypted-media.Motivation and Context
MCP Apps that play video need Permission Policy features the spec does not list: the Fullscreen API, Picture-in-Picture, autoplay with sound and Encrypted Media Extensions for DRM playback (#757).
The closed list in
McpUiResourcePermissionsalso means every new feature needs a spec change, which #320 wants to move away from.Four changes:
clipboard-writeas the canonical key for clipboard write access and keepclipboardWriteas a deprecated legacy alias.fullscreen,picture-in-picture,autoplayandencrypted-media.McpUiResourcePermissions. Hosts SHOULD recognize the named keys, MAY honor other feature names, and MUST NOT apply keys that are not valid feature names.This mix of named keys and an open map follows an existing pattern, for example in this SDK's
McpUiHostContext.How Has This Been Tested?
src/app-bridge.test.ts: unit tests forbuildAllowAttributecovering the named keys, pass-through, invalid keys and the alias.npm run build,npm test,npm run prettierandtypedoc --treatValidationWarningsAsErrorspass.Both the outer and the inner iframe get
allow="fullscreen; picture-in-picture; autoplay; encrypted-media"and the native fullscreen control is enabled; without the declaration there is noallowattribute and the control is disabled.Breaking Changes
None, existing keys keep their meaning.
Types of changes
Checklist
Additional context
presentationandremote-playbackare not Permission Policy features and need a different mechanism.