fix: reject PWA access if network conditions are configured - #15271
Merged
Merged
Conversation
Lightning00Blade
approved these changes
Jul 29, 2026
Merged
pull Bot
pushed a commit
to Pet3cy/chrome-devtools-mcp
that referenced
this pull request
Aug 10, 2026
## What / Why Adds an opt-in Progressive Web Apps tool category that exposes the installed web app lifecycle to MCP clients and agents. The browser-level PWA APIs were introduced in Puppeteer 25.4.0 (puppeteer/puppeteer#15235). The current base uses Puppeteer 25.5.0, which also enforces URL restrictions for browser-level PWA operations (puppeteer/puppeteer#15271). ## Tools - `install_pwa` - `launch_pwa` - `get_os_app_state` - `uninstall_pwa` The category is disabled by default and enabled with `--category-pwa`. These are browser-scoped operations and do not require a selected page. Callers provide the resolved manifest ID and, for installation, an explicit page or bundle URL. `open_current_page_in_app` and automatic current-page installation are intentionally deferred until Puppeteer exposes page-native APIs with reliable loaded-document and browser-context semantics. ## Compatibility and safety - Requires a pipe-launched browser. The CLI rejects `--category-pwa` when combined with `--auto-connect`, `--browser-url`, or `--ws-endpoint`. - Puppeteer rejects PWA operations when URL allow/block restrictions are configured, preventing browser-internal PWA fetch and redirect flows from bypassing the configured policy. - File-based install bundles are validated against the MCP filesystem roots. - DevTools installation defaults to browser display mode unless `displayMode: "standalone"` is supplied. Launch uses the app's saved display preference. ## Testing - PWA tests cover lifecycle/state, standalone launch, successful explicit-URL launch, use without a selected page, file-bundle path validation, OS-state output, and selected-page fallback after uninstall. - Existing off-by-default category tests cover PWA tool registration and opt-in exposure. - Generated README, tool reference, CLI metadata, and telemetry metrics are updated. - Type checking, formatting, targeted tests, broad supporting repository tests, third-party notice validation, and diff checks pass locally. - Validated against Chrome for Testing 150 and a local Chromium/Edge build. - A real stdio MCP lifecycle passed end to end with the final four-tool design: category gating, explicit install, OS state, standalone launch, selecting and scripting the returned page, uninstall, selection fallback, and post-uninstall state rejection. Refs ChromeDevTools#2270
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Turns out network conditions CDP command is not available for PWA targets.
Refs: ChromeDevTools/chrome-devtools-mcp#2430