Skip to content

feat: use Trusted Types automatically in the framework - #536

Merged
Mohamed Mansour (mohamedmansour) merged 4 commits into
mainfrom
mohamedmansour-framework-trusted-types
Sep 15, 2026
Merged

Mohamed Mansour (mohamedmansour) merged 4 commits into
mainfrom
mohamedmansour-framework-trusted-types

Conversation

@mohamedmansour

@mohamedmansour Mohamed Mansour (mohamedmansour) commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

WebUI now uses Trusted Types automatically for native compiled templates and generated CSS import maps. The private, fixed-name webui policy is created on first use. There is no configuration API, setup entry point, special import order, or global policy state.

Applications choose enforcement through CSP:

require-trusted-types-for 'script'; trusted-types webui

Policy creation failures are explicit; browsers without Trusted Types retain normal string rendering. Raw state HTML and arbitrary script/source strings are never promoted. Rejected raw-HTML updates preserve existing DOM and allow remaining queued updates to proceed.

Includes updated developer documentation and regression coverage. Router/CLI integration remains separate; no dependency or release changes.

Validation

  • Framework TypeScript compilation and 360 unit tests passed.
  • Browser fixture typecheck and 16 Edge browser tests passed: automatic hydration/client mounts, no global trust capability, enforced versus unenforced raw HTML, policy-name denial with and without enforcement, and existing raw-HTML regressions.
  • cargo xtask check: all stages passed in 177.3s, including docs.
  • Used installed Edge with a temporary local test-server configuration; committed tests retain standard CI configuration.

Size

Compared with the previous explicit-configuration implementation (13b0a17e), the standalone minified policy module shrank from 2,133 to 1,242 bytes (42%). A production framework bundle with Trusted Types enabled shrank from 78,344 to 77,461 bytes (gzip: 24,778 to 24,484).

Automatic support is now included for every app: relative to the previous bundle that omitted opt-in code, the cost is 555 minified bytes / 208 gzip bytes. The policy and weak maps remain lazy; unsupported browsers allocate neither.

Scope: 18 files, +742/-33.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Comment thread packages/webui-framework/src/template-element.ts
Comment thread packages/webui-framework/src/trusted-types-policy.ts Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@mohamedmansour Mohamed Mansour (mohamedmansour) changed the title feat: add explicit Trusted Types support to the framework feat: use Trusted Types automatically in the framework Sep 15, 2026
@mohamedmansour
Mohamed Mansour (mohamedmansour) merged commit a357c26 into main Sep 15, 2026
35 checks passed
@mohamedmansour
Mohamed Mansour (mohamedmansour) deleted the mohamedmansour-framework-trusted-types branch September 15, 2026 22:37
Mohamed Mansour (mohamedmansour) added a commit that referenced this pull request Sep 18, 2026
## Release

Bumps WebUI to `0.0.29`.

Previous release tag: `v0.0.28`

## Changes since `v0.0.28`

Features:

- Ship version-matched AI authoring guidance with `@microsoft/webui`,
using a lightweight skill that reads the installed package's reference
(feat: bundle versioned AI guidance with WebUI #522 by @mohamedmansour).
- Add plugin-aware component discovery, with filename-based HTML
components and manifest-driven FAST components (feat: add plugin-aware
component discovery #524 by @mohamedmansour).
- Add WebUI Press `--show=all|content` for shell-free documentation
views that preserve SSR, hydration, authored examples, and accessible
theme behavior (feat: add WebUI Press content mode #525 by
@mohamedmansour).
- Automatically support Trusted Types for compiled templates and
generated CSS import maps without promoting arbitrary state HTML to
trusted content (feat: use Trusted Types automatically in the framework
#536 by @mohamedmansour).
- Keep explicit streaming imports lightweight so applications can load
streaming support early and application code later (feat: keep explicit
streaming imports lightweight #539 by @mohamedmansour).
- Render tree-shaped state with file-scoped named `<for id="...">`
bodies, including forward references and recursive reuse without extra
client runtime code. Use unbraced `each="item in items"`; the legacy
`template` spelling and FAST component references produce actionable
diagnostics (feat: add file-scoped recursive for loops #547 by
@mohamedmansour).

Fixes:

- Preserve table-rooted hydration ownership and correctly compile
whitespace-bearing, nested directives, preventing duplicate controls
after reactive updates. Rebuild templates to receive the compiler fix
(fix: preserve table-rooted hydration paths #512 by @mohamedmansour;
fix: align client directive parsing with the HTML scanner #531 by
@mohamedmansour).
- Emit reachable stylesheets and templates in deterministic traversal
order. External plugin implementations must adapt the affected
`HandlerPlugin` and bootstrap component collection interfaces from hash
sets to slices (fix: render reachable-component ordering
deterministically #519 by @janechu).
- Resolve bare CEM module specifiers through their owning packages,
respecting export maps, package boundaries, and cache invalidation when
nearer dependencies appear (fix: resolve bare CEM module specifiers #528
by @janechu).
- Prevent spurious dev-server rebuilds from read-only filesystem
activity and recursive traversal of linked workspace dependencies
(Improve benchmark telemetry and dev-server watching #521 by
@mohamedmansour).
- Update rustls to address TLS 1.3 handshake encryption-level validation
advisory RUSTSEC-2026-0285 (fix: update rustls to address
RUSTSEC-2026-0285 #533 by @mohamedmansour).
- Forward bare boolean and ARIA component inputs into SSR state while
preserving empty literal attributes and existing conditional boolean
bindings (fix: forward HTML component inputs during SSR #540 by
@mohamedmansour).
- Preserve sibling route declaration order across SSR and client routing
so equally specific routes select the correct pending and error
boundaries (fix: preserve route order for pending and error boundaries
#541 by @mohamedmansour).
- Handle skipped or superseded router view transitions without unhandled
animation rejections, while preserving route-commit errors and
responsive subsequent navigation (fix: handle router view transition
rejections #543 by @mohamedmansour).
- Wait for active dev-server rebuilds and their bundler subprocesses
before graceful shutdown, preventing output writes after the server
exits (fix: wait for dev-server rebuilds during shutdown #546 by
@mohamedmansour).
- Preserve global theme defaults when custom properties are overridden
only by scoped selectors or conditional rules, so unmatched component
instances retain their intended colors (fix: preserve theme defaults
under scoped CSS overrides #548 by @mohamedmansour).

Docs:

- Add a data-driven Benchmark Explorer, centralize performance guidance,
distinguish independent SSR/browser metrics, and publish resource
telemetry with accessible methodology details (docs: centralize
performance guidance and benchmark data #486 by @mohamedmansour; Improve
benchmark telemetry and dev-server watching #521 by @mohamedmansour).
- Update AI reference installation and migration guidance while
retaining `/ai`, and clarify plugin-specific discovery and FAST
converted-template requirements (feat: bundle versioned AI guidance with
WebUI #522 by @mohamedmansour; feat: add plugin-aware component
discovery #524 by @mohamedmansour).
- Document owned Rust partial rendering, streaming state ownership, and
watcher hashing benchmarks, including measurement scope and tradeoffs
(perf: reduce partial response allocations #510 by @mohamedmansour;
perf: move streaming command processing off async workers #529 by
@mohamedmansour; perf: bound watcher hashing memory with reusable
scratch #530 by @mohamedmansour).
- Document automatic Trusted Types support, CSP enforcement, and
first-declared precedence for equally specific routes and their
pending/error boundaries (feat: use Trusted Types automatically in the
framework #536 by @mohamedmansour; fix: preserve route order for pending
and error boundaries #541 by @mohamedmansour).
- Explain named recursive loops and their compatibility limits, scoped
CSS token defaults, and router view-transition error handling (feat: add
file-scoped recursive for loops #547 by @mohamedmansour; fix: preserve
theme defaults under scoped CSS overrides #548 by @mohamedmansour; fix:
handle router view transition rejections #543 by @mohamedmansour).

Maintenance:

- Reduce partial-response and per-render allocations through owned state
projection, borrowed graph traversal, scalar formatting, and borrowed
nested route trees. Rust callers use ownership-taking
`Protocol::render_partial(Value, ...)`; JSON boundaries retain
`render_partial_json` (perf: reduce partial response allocations #510 by
@mohamedmansour; perf: cut per-render handler allocations #511 by
@mohamedmansour; perf: avoid cloning nested route trees #513 by
@mohamedmansour).
- Move streaming command deserialization, validation, and default
preparation onto the existing blocking renderer, transferring owned
records and state rather than cloning retained projections (perf: move
streaming command processing off async workers #529 by @mohamedmansour).
- Bound watcher hashing content storage to one reusable 8 KiB buffer
instead of repeated file-sized allocations while preserving invalidation
behavior (perf: bound watcher hashing memory with reusable scratch #530
by @mohamedmansour).
- Parallelize release WASM builds and artifact staging, and consolidate
dependency scanning before release jobs (chore: parallelize release
pipeline work #509 by @mohamedmansour).
- Refresh compatible Rust and JavaScript dependencies and migrate
repository tooling and CI to pnpm 12.3.4 while preserving existing audit
constraints (chore: update dependencies to latest compatible versions
#534 by @mohamedmansour).

## Validation

- `cargo xtask check`
- `pnpm --dir crates/webui-press test` (16 passed).
- `pnpm --dir packages/webui-framework exec playwright test
recursive-repeat --workers=2 --reporter=line` (6 passed).
- `pnpm --dir packages/webui-router exec playwright test --grep "view
transition rejection ownership" --workers=2 --reporter=line` (4 passed).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants