Open questions
Status: draft. Unresolved means unresolved. Nothing on this page is a decision.
P0: blocks any third-party extension
- The HTML/CSS allowlist. Is the browser Sanitizer API alone enough, or do we need our own?
- Which security claims can UIBubbles responsibly make? Decide after the adversarial test suite exists.
- Worker-DOM library. Shopify remote-dom, AMP worker-dom, or our own.
- Benchmark. Is a per-extension iframe plus one worker per Bubble materially lighter than one iframe per Bubble?
- Which headless grants need explicit user confirmation, and are they per session or persistent?
- Provider identity and trust. Key pinning and rotation rules, revocation, and the exact URL normalisation.
P1: blocks protocol 0.1
- Canonical wire format for Declarative Bubbles. Can or should A2UI or OpenUI be the basis?
- How methods are named and versioned. Is a semver range in
usesenough? - How glue walls are declared and typed. Do event payloads reuse JSContact and JSCalendar?
- Host-mediated networking. How exactly does it work, and how are dangerous combinations such as data access plus open network refused?
- Runtime permission requests. How does a Bubble ask for more capability after it is running?
- Surface constraints. How are dimensions and display modes negotiated?
- Accessibility semantics. How are they represented so they survive mirroring and text fallback?
- Themes and design tokens. How do they pass to Declarative and Worker Bubbles?
- Composition bindings. How do glue bindings work beyond matching
emitstoaccepts? - State ownership. Who owns Bubble state when a Bubble is popped and later restored?
P2: later
- What does pin mean across sessions and devices? What does pinning a foam mean?
- Portability. How portable can Declarative Bubbles realistically be across web, native and TUI?
- Discovery. Beyond direct id addressing, how are extensions found? Is a registry needed, and can MCP advertise Bubble capabilities?
- Swappable providers behind abstract capabilities (
contacts.chooseserved by whichever provider the user prefers). Outlined only; Web Intents is the warning. - Conformance. The minimum requirements for a Host and for an extension.
Project questions
- Licensing. Apache-2.0 for code and CC-BY-4.0 for documentation and spec is the provisional choice.
- Governance of a public standard. Undecided. Nothing will be claimed until it is decided.
- Repository layout. One repository (site, spec, runtime) for speed, or separate repositories?
- When uibubbles.org goes public. The domain is on Cloudflare; the site is not deployed yet.
- Signing and provenance at scale, and cross-device pin state. Matter only at third-party scale.