Skip to content

Extend UI resource permissions - #799

Open
jmsn wants to merge 4 commits into
modelcontextprotocol:mainfrom
jmsn:feat/open-ended-permissions
Open

jmsn wants to merge 4 commits into
modelcontextprotocol:mainfrom
jmsn:feat/open-ended-permissions

Conversation

@jmsn

@jmsn jmsn commented Oct 6, 2026 •

Copy link
Copy Markdown

Make UI resource permissions open-ended and add named permissions fullscreen, picture-in-picture, autoplay and encrypted-media.

Motivation and Context

MCP Apps that play video need Permission Policy features the spec does not list: the Fullscreen API, Picture-in-Picture, autoplay with sound and Encrypted Media Extensions for DRM playback (#757).

The closed list in McpUiResourcePermissions also means every new feature needs a spec change, which #320 wants to move away from.

Four changes:

  1. Use Permission Policy feature names verbatim as permission keys, without a key-to-feature-name translation step: add clipboard-write as the canonical key for clipboard write access and keep clipboardWrite as a deprecated legacy alias.
  2. Add named permissions for fullscreen, picture-in-picture, autoplay and encrypted-media.
  3. Allow requesting Permission Policy features that are not explicitly named: add a string index signature to McpUiResourcePermissions. Hosts SHOULD recognize the named keys, MAY honor other feature names, and MUST NOT apply keys that are not valid feature names.
  4. Declare the four media permissions in the video example, so the native video controls show them taking effect in basic-host.

This mix of named keys and an open map follows an existing pattern, for example in this SDK's McpUiHostContext.

How Has This Been Tested?

  • src/app-bridge.test.ts: unit tests for buildAllowAttribute covering the named keys, pass-through, invalid keys and the alias.
  • npm run build, npm test, npm run prettier and typedoc --treatValidationWarningsAsErrors pass.
  • Manually, using basic-host with the video MCP example in Chrome:
    Both the outer and the inner iframe get allow="fullscreen; picture-in-picture; autoplay; encrypted-media" and the native fullscreen control is enabled; without the declaration there is no allow attribute and the control is disabled.

Breaking Changes

None, existing keys keep their meaning.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

Additional context

jmsn added 4 commits October 6, 2026 14:39
Permission keys are the Permission Policy feature names. clipboardWrite
stays as a legacy alias and is deprecated in its favor.
Extend McpUiResourcePermissions with fullscreen, picture-in-picture,
autoplay and encrypted-media.
Add a string index signature to McpUiResourcePermissions so views can
request features without a named key, using the feature name verbatim.
The example declares fullscreen, picture-in-picture, autoplay and
encrypted-media; the native video controls show the first two taking
effect in basic-host.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant