This is my braindump of a conversation between @LukasReschke and myself.
It often happens that we want to introduce new behaviour. This can be for performance benefits or security considerations. However chaning the default behaviour would kill a lot of apps and is thus unacceptable.
Take for example #1127 we could enforce that already with our CSP policy. But that would kill a lot of apps out there. While it is a very good security measure that should be opt-out (if at all) and not opt-in.
So we came up with the idea of an AppAPI (or AAPI). Like we assume the current state AAPIv1. Now if we introduce a breaking change (and lets face it sometimes we have to). We have to create a new AAPI, v2. An app can then declare itself AAPIv2 compatible in the info.xml and we can enable additional secutiry and performance enhancements.
This approach gives us the ability to introduce new default behaviour that overall benefit the App Eco System while not having a hard break point. We will maintain the default deprecation period of 3 years to fase out a deprecated AAPI version.
Toughts? @nickvergessen @icewind1991 @blizzz @MorrisJobke @BernhardPosselt
This is my braindump of a conversation between @LukasReschke and myself.
It often happens that we want to introduce new behaviour. This can be for performance benefits or security considerations. However chaning the default behaviour would kill a lot of apps and is thus unacceptable.
Take for example #1127 we could enforce that already with our CSP policy. But that would kill a lot of apps out there. While it is a very good security measure that should be opt-out (if at all) and not opt-in.
So we came up with the idea of an AppAPI (or AAPI). Like we assume the current state AAPIv1. Now if we introduce a breaking change (and lets face it sometimes we have to). We have to create a new AAPI, v2. An app can then declare itself AAPIv2 compatible in the info.xml and we can enable additional secutiry and performance enhancements.
This approach gives us the ability to introduce new default behaviour that overall benefit the App Eco System while not having a hard break point. We will maintain the default deprecation period of 3 years to fase out a deprecated AAPI version.
Toughts? @nickvergessen @icewind1991 @blizzz @MorrisJobke @BernhardPosselt