P2: Connect WebMCP invocation cancellation and verify the native browser lifecycle #837

Open
opened 2026-10-02 13:23:06 +00:00 by kayg · 2 comments
Owner

Research follow-up under #484. Source snapshot: c4a61e8cf090170f35b1bed3350d9de20c83ecd5.

WebMCP already detects the current document entry and the older navigator entry, loads only after opt-in, confirms writes and repeats access checks.

Evidence:

  • apps/web/src/lib/webmcp/generated.ts:send does not receive an invocation abort signal.
  • registerGeneratedTools checks the registration signal before dispatch, but does not bridge a running invocation cancellation into its fetch.
  • Generated descriptions often fall back to operation-ID words.
  • Registry-based source and substituted-context tests cannot prove native discovery, permission policy or cancellation behavior in a supported browser.

Acceptance:

  1. Bridge supported invocation abort into the shared request path and cancel pending confirmation cleanly; preserve route-only authority and step-up checks.
  2. Keep opt-out/sign-out/revoke behavior correct for tools already registered or executing.
  3. Test real browser registration, discovery, execute, cancellation and same-origin policy against a pinned implementation. Label unsupported browsers accurately.
  4. Reuse better generated descriptions and meaningful structured errors; normal User controls remain fully usable without this API.
  5. Preserve the changing draft boundary. Do not claim universal browser consent or expose cross-origin tools without a decided need.

Related #484; source review WebMCP. No UI code changes or native browser failure were produced by this research job.

Full evidence and decisions: docs/research/agent-surfaces.md on branch job/research-surfaces. No runtime change was made by the research job.

Research follow-up under #484. Source snapshot: `c4a61e8cf090170f35b1bed3350d9de20c83ecd5`. WebMCP already detects the current document entry and the older navigator entry, loads only after opt-in, confirms writes and repeats access checks. Evidence: - `apps/web/src/lib/webmcp/generated.ts:send` does not receive an invocation abort signal. - `registerGeneratedTools` checks the registration signal before dispatch, but does not bridge a running invocation cancellation into its fetch. - Generated descriptions often fall back to operation-ID words. - Registry-based source and substituted-context tests cannot prove native discovery, permission policy or cancellation behavior in a supported browser. Acceptance: 1. Bridge supported invocation abort into the shared request path and cancel pending confirmation cleanly; preserve route-only authority and step-up checks. 2. Keep opt-out/sign-out/revoke behavior correct for tools already registered or executing. 3. Test real browser registration, discovery, execute, cancellation and same-origin policy against a pinned implementation. Label unsupported browsers accurately. 4. Reuse better generated descriptions and meaningful structured errors; normal User controls remain fully usable without this API. 5. Preserve the changing draft boundary. Do not claim universal browser consent or expose cross-origin tools without a decided need. Related #484; source review WebMCP. No UI code changes or native browser failure were produced by this research job. Full evidence and decisions: `docs/research/agent-surfaces.md` on branch `job/research-surfaces`. No runtime change was made by the research job.
Author
Owner

Copy audit evidence for the browser tools

These descriptions and errors go to the connected browser-tools client. They are user-visible in that client.

  • apps/web/src/lib/webmcp/tools.ts:305: title Manage Calendar feeds; description List and manage published Calendar feeds and external read-only Calendar subscriptions through the authenticated Calendar API. Use a plain title such as Manage shared calendars and a description such as List and manage the calendars you share and the calendars you follow.
  • apps/web/src/lib/webmcp/generated.ts:86,93 and apps/web/src/lib/webmcp/tools.ts:367: WebMCP is disabled in Settings → Apps & Devices. / WebMCP is disabled in Settings → Apps. Say Browser tools are turned off. Turn them on in Settings → Apps.
  • apps/web/src/lib/webmcp/tools.ts:349: At least one external Calendar setting is required. Say Choose at least one calendar to continue.

Owner rule: no protocol names or technical terms in user-facing copy when a plain word works. This also fits this issue's acceptance item 4: use meaningful descriptions and errors.

Test idea: call one calendar tool while browser tools are off, then open its description and use a calendar link. Check the title, description and error in the connected client.

Copy audit evidence for the browser tools These descriptions and errors go to the connected browser-tools client. They are user-visible in that client. - `apps/web/src/lib/webmcp/tools.ts:305`: title `Manage Calendar feeds`; description `List and manage published Calendar feeds and external read-only Calendar subscriptions through the authenticated Calendar API.` Use a plain title such as `Manage shared calendars` and a description such as `List and manage the calendars you share and the calendars you follow.` - `apps/web/src/lib/webmcp/generated.ts:86,93` and `apps/web/src/lib/webmcp/tools.ts:367`: `WebMCP is disabled in Settings → Apps & Devices.` / `WebMCP is disabled in Settings → Apps.` Say `Browser tools are turned off. Turn them on in Settings → Apps.` - `apps/web/src/lib/webmcp/tools.ts:349`: `At least one external Calendar setting is required.` Say `Choose at least one calendar to continue.` Owner rule: no protocol names or technical terms in user-facing copy when a plain word works. This also fits this issue's acceptance item 4: use meaningful descriptions and errors. Test idea: call one calendar tool while browser tools are off, then open its description and use a calendar link. Check the title, description and error in the connected client.
Author
Owner

One more set of plain-language strings in the browser-tools descriptions

  • apps/web/src/lib/webmcp/tools.ts:165: List the first 100 accessible items in the Home root or a folder ID. → List up to 100 items in Home or a folder.
  • :220: Update the message read state at its provider after User confirmation. → Change whether this message is marked as read in your mail account, after you confirm.
  • :222: Mark this Mail message as read at its provider? / Mark this Mail message as unread at its provider? → Mark this message as read? / Mark this message as unread?
  • :229: Choose when opening messages marks them read at the provider, after User confirmation. → Choose when opened messages are marked as read.

Test idea: inspect the generated tool list and confirmation text in a connected client. Check the copy with no folders, one folder and each read-marking choice.

One more set of plain-language strings in the browser-tools descriptions - `apps/web/src/lib/webmcp/tools.ts:165`: `List the first 100 accessible items in the Home root or a folder ID.` → `List up to 100 items in Home or a folder.` - `:220`: `Update the message read state at its provider after User confirmation.` → `Change whether this message is marked as read in your mail account, after you confirm.` - `:222`: `Mark this Mail message as read at its provider?` / `Mark this Mail message as unread at its provider?` → `Mark this message as read?` / `Mark this message as unread?` - `:229`: `Choose when opening messages marks them read at the provider, after User confirmation.` → `Choose when opened messages are marked as read.` Test idea: inspect the generated tool list and confirmation text in a connected client. Check the copy with no folders, one folder and each read-marking choice.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#837
No description provided.