Skip to content

docs: clarify PostMessageTransport target origin - #777

Open
flowtrader2016 wants to merge 1 commit into
modelcontextprotocol:mainfrom
flowtrader2016:docs/clarify-postmessage-target-origin
Open

flowtrader2016 wants to merge 1 commit into
modelcontextprotocol:mainfrom
flowtrader2016:docs/clarify-postmessage-target-origin

Conversation

@flowtrader2016

@flowtrader2016 flowtrader2016 commented Sep 17, 2026

Copy link
Copy Markdown

Clarify how PostMessageTransport.send() uses the recipient window and wildcard target origin.

Motivation and Context

The existing comment says that using "*" makes messages visible to all frames. The implementation calls postMessage on eventTarget, so delivery targets that window. The wildcard allows delivery regardless of the target window's origin, as specified by the HTML Standard.

Update the comment to describe that behavior and retain the guidance to validate the message source.

How Has This Been Tested?

  • npm run build — passed.
  • npm test — 439 passed, 1 skipped, 0 failed.
  • npm run prettier — passed.
  • npm exec typedoc -- --treatValidationWarningsAsErrors --emit none — passed.
  • git diff --check — passed.

Documentation-only change; no new tests added. Browser E2E and the cross-platform CI matrix were not run locally.

Breaking Changes

None. Runtime behavior is unchanged.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling — not applicable to this documentation-only change.
  • I have added or updated documentation as needed

Additional context

AI assistance: Codex researched and authored this documentation correction and PR draft, and ran the local validation commands.

@flowtrader2016
flowtrader2016 marked this pull request as ready for review September 17, 2026 19:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant