Skip to content

Apps API Version #1238

Description

@rullzer

This is my braindump of a conversation between @LukasReschke and myself.

It often happens that we want to introduce new behaviour. This can be for performance benefits or security considerations. However chaning the default behaviour would kill a lot of apps and is thus unacceptable.

Take for example #1127 we could enforce that already with our CSP policy. But that would kill a lot of apps out there. While it is a very good security measure that should be opt-out (if at all) and not opt-in.

So we came up with the idea of an AppAPI (or AAPI). Like we assume the current state AAPIv1. Now if we introduce a breaking change (and lets face it sometimes we have to). We have to create a new AAPI, v2. An app can then declare itself AAPIv2 compatible in the info.xml and we can enable additional secutiry and performance enhancements.

This approach gives us the ability to introduce new default behaviour that overall benefit the App Eco System while not having a hard break point. We will maintain the default deprecation period of 3 years to fase out a deprecated AAPI version.

Toughts? @nickvergessen @icewind1991 @blizzz @MorrisJobke @BernhardPosselt

Activity

  1. blizzz commented on Sep 2, 2016

    @blizzz
    Member

    conparable to Androids API Level?

  2. rullzer commented on Sep 2, 2016

    @rullzer
    MemberAuthor

    Yes similar

  3. MorrisJobke commented on Sep 2, 2016

    @MorrisJobke
    Member

    The only problem I see here is how we accomplish to run app code in level 1 together at the same time with an app in level 2 ... we then would need for example two different middleware systems -> sounds like a nice idea but could cause heavy headaches once we want to implement this.

  4. rullzer commented on Sep 2, 2016

    @rullzer
    MemberAuthor

    There was a discussion on IRC which basically boiled down to.

    • No API levels since we are to small to maintain it properly.
    • New controllers that do all kinds of fancy stuff. Deprecate old ones. Then the middleware can just check for the controller type
  5. rullzer commented on Sep 4, 2016

    @rullzer
    MemberAuthor

    Another thing we came up with was annotations.

    But all in all we will most likely end up with

    1. Announce new way + explain why
    2. Start logging deprecation warnings
    3. At some point switch over and break (after the 3 year dep period most likely).
  6. rullzer commented on Sep 4, 2016

    @rullzer
    MemberAuthor

    Altough I must admit I'm still not entirely happy about this.
    As it basically makes a lot of security/performance things opt in for a long time. But probabaly not much we can do there right now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions