Similar to many other IWA APIs, I consulted the partners with whom we work
and who will be using the API over virtual meetings. This makes sense
because IWA APIs are available to only a handful of trusted partners.
If that is not the way to go, I can ask them to provide a public feedback
in whatever thread you find the most appropriate.

On Mon, Jul 20, 2026 at 8:48 PM Alex Russell <[email protected]>
wrote:

> It's very disappointing that the TAG has declined to review these
> features. In future, I think we (API OWNERS) should be setting up some sort
> of a parallel system of API review in cases where the TAG is refusing to do
> its duty.
>
> Was there developer feedback from dev trials? Why do we have confidence
> that this is the right design?
>
> Best,
>
> Alex
>
> On Thursday, July 16, 2026 at 12:06:03 AM UTC-7 Mike Taylor wrote:
>
>> LGTM2
>> On 7/15/26 6:58 p.m., Reilly Grant wrote:
>>
>> IWA OWNER LGTM
>>
>> I think eventually this feature could be replaced by proposed APIs for
>> programmatic PWA self-installation and web application stores. However the
>> current IWA restriction is appropriate given the potential for application
>> spoofing.
>> Reilly Grant | Software Engineer | [email protected] | Google Chrome
>> <https://www.google.com/chrome>
>>
>>
>> On Wed, Jul 15, 2026 at 8:38 AM Chris Harrelson <[email protected]>
>> wrote:
>>
>>> LGTM1
>>>
>>> On Wed, Jul 15, 2026 at 4:22 AM Chromestatus <
>>> [email protected]> wrote:
>>>
>>>> *Contact emails*
>>>> [email protected]
>>>>
>>>> *Explainer*
>>>> https://github.com/WICG/sub-apps
>>>>
>>>> *Specification*
>>>> https://wicg.github.io/sub-apps
>>>>
>>>> *Design docs*
>>>>
>>>> https://github.com/WICG/sub-apps
>>>>
>>>> *Summary*
>>>> Sub apps allow developers to create multiple apps under a single
>>>> Isolated Web App ([IWA](https://chromeos.dev/en/web/isolated-web-apps))
>>>> installation. Each Sub app has its own distinct name, icons and OS
>>>> integrations. Sub apps appear on the desktop shelf with a distinct identity
>>>> from the parent IWA, offering separate OS capabilities, such as file type
>>>> association. This allows a single software package to present different,
>>>> isolated functionalities to the user while maintaining a single, unified
>>>> IWA install and update process. There are three new enterprise policies
>>>> available to control the Sub apps API: -
>>>> [DefaultSubAppsWithoutPromptsSetting](
>>>> https://chromeenterprise.google/policies/#DefaultSubAppsWithoutPromptsSetting)
>>>> specifies globally (for all IWAs) if user permission prompts are required
>>>> to install Sub apps. The policies below can override this default. -
>>>> [SubAppsWithoutPromptsAllowedForOrigins](
>>>> https://chromeenterprise.google/policies/#SubAppsWithoutPromptsAllowedForOrigins)
>>>> specifies a list of IWA URLs that can add or update Sub apps without user
>>>> permission prompts. - [SubAppsWithoutPromptsBlockedForOrigins](
>>>> https://chromeenterprise.google/policies/#SubAppsWithoutPromptsBlockedForOrigins)
>>>> specifies a list of IWA URLs that can add Sub apps with user permission
>>>> prompts only.
>>>>
>>>> *Blink component*
>>>> Content>WebApps
>>>> <https://issues.chromium.org/issues?q=customfield1222907:%22Content%3EWebApps%22>
>>>>
>>>> *Web Feature ID*
>>>> Missing feature
>>>>
>>>> *Motivation*
>>>> Without this API developers are forced into splitting the application
>>>> into separate ones which complicates distribution or bundle everything into
>>>> a single huge application that can potentially confuse users.
>>>>
>>>> *Initial public proposal*
>>>> https://github.com/WICG/proposals/issues/282
>>>>
>>>> *TAG review*
>>>> Tag does not review Isolated Web Apps. It was stated publicly here
>>>> https://github.com/w3ctag/design-reviews/issues/842#issuecomment-2917031448
>>>>
>>>> *TAG review status*
>>>> Pending
>>>>
>>>> *Goals for experimentation*
>>>> None
>>>>
>>>> *Risks*
>>>>
>>>>
>>>> *Interoperability and Compatibility*
>>>> Other browsers may choose to implement this API.
>>>>
>>>> *Gecko*: No signal
>>>>
>>>> *WebKit*: No signal
>>>>
>>>> *Web developers*: No signals
>>>>
>>>> *Other signals*:
>>>>
>>>> *Security*
>>>> Sub-apps share origin identity and all local data stores with their
>>>> parent app, exposing them to standard same-origin security boundaries.
>>>> Permission grants are shared bidirectionally; granting a permission to a
>>>> sub-app automatically extends that permission to the parent app. There is a
>>>> risk of identity spoofing and launcher hijacking, which is mitigated by
>>>> restricting the API to isolated contexts. Registering custom OS
>>>> integrations requires explicit user approval to prevent unauthorized
>>>> protocol handling or file type hijacking.
>>>>
>>>> *WebView application risks*
>>>>
>>>> Does this intent deprecate or change behavior of existing APIs, such
>>>> that it has potentially high risk for Android WebView-based applications?
>>>> *No information provided*
>>>>
>>>>
>>>> *Debuggability*
>>>> There's no special devTools support for this feature. It is possible to
>>>> add sub apps, remove and list them via devTools console raw javascript
>>>> execution.
>>>>
>>>> *Will this feature be supported on all six Blink platforms (Windows,
>>>> Mac, Linux, ChromeOS, Android, and Android WebView)?*
>>>> No
>>>> This feature is implemented on desktop platforms, although it will only
>>>> be available to the end users on platforms that support Isolated Web Apps,
>>>> which is currently only ChromeOS. Android is excluded because installing
>>>> arbitrary apps is complicated there and needs additional work.
>>>>
>>>> *Is this feature fully tested by web-platform-tests
>>>> <https://chromium.googlesource.com/chromium/src/+/main/docs/testing/web_platform_tests.md>?*
>>>> No
>>>> JS API interface tests are in
>>>> third_party/blink/web_tests/external/wpt/subapps.
>>>> https://wpt.fyi/results/subapps?label=master&label=experimental&aligned&q=subapps
>>>> More complete tests that cover all cases are in
>>>> chrome/browser/web_applications/sub_apps/sub_apps_service_impl_browsertest.cc
>>>>
>>>> *DevTrial instructions*
>>>> https://github.com/vkrot-cell/subapps-demo
>>>>
>>>> *Flag name on about://flags*
>>>> #enable-sub-apps
>>>>
>>>> *Finch feature name*
>>>> SubApps
>>>>
>>>> *Rollout plan*
>>>> Will ship enabled for all users
>>>>
>>>> *Requires code in //chrome?*
>>>> True
>>>>
>>>> *Tracking bug*
>>>> https://buganizer.corp.google.com/issues/414729785
>>>>
>>>> *Launch bug*
>>>> https://launch.corp.google.com/launch/4466158
>>>>
>>>> *Measurement*
>>>> Separate programmatic counters for the .idl methods and attributes (via
>>>> MeasureAs) are included to track the stats for API usage: SubAppsAdd
>>>> SubAppsRemove SubAppsList
>>>>
>>>> *Availability expectation*
>>>> Feature is available only in Isolated Web Apps on desktop platforms.
>>>> https://chromestatus.com/feature/5146307550248960
>>>>
>>>> *Adoption expectation*
>>>> Expected to be used initially by a small number of developers inside
>>>> Isolated Web Apps.
>>>>
>>>> *Adoption plan*
>>>> Working directly with developers that are planning to rely on the API.
>>>>
>>>> *Estimated milestones*
>>>> Shipping on desktop 153
>>>> DevTrial on desktop 150
>>>>
>>>> *Anticipated spec changes*
>>>>
>>>> Open questions about a feature may be a source of future web compat or
>>>> interop issues. Please list open issues (e.g. links to known github issues
>>>> in the project for the feature specification) whose resolution may
>>>> introduce web compat/interop risk (e.g., changing to naming or structure of
>>>> the API in a non-backward-compatible way).
>>>> *No information provided*
>>>>
>>>> *Link to entry on the Chrome Platform Status*
>>>> https://chromestatus.com/feature/6260680824061952?gate=4662441016426496
>>>>
>>>> *Links to previous Intent discussions*
>>>> Intent to Prototype:
>>>> https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6a3408fc.3af95f39.17d45c.0404.GAE%40google.com
>>>>
>>>>
>>>> This intent message was generated by Chrome Platform Status
>>>> <https://chromestatus.com>.
>>>> --
>>>> You received this message because you are subscribed to the Google
>>>> Groups "blink-dev" group.
>>>> To unsubscribe from this group and stop receiving emails from it, send
>>>> an email to [email protected].
>>>> To view this discussion visit
>>>> https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6a576d60.854c7482.198413.00e8.GAE%40google.com
>>>> <https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6a576d60.854c7482.198413.00e8.GAE%40google.com?utm_medium=email&utm_source=footer>
>>>> .
>>>>
>>> --
>>> You received this message because you are subscribed to the Google
>>> Groups "blink-dev" group.
>>> To unsubscribe from this group and stop receiving emails from it, send
>>> an email to [email protected].
>>> To view this discussion visit
>>> https://groups.google.com/a/chromium.org/d/msgid/blink-dev/CAOMQ%2Bw_tGRNHZe40U3i67XLWbsXdkzRTisdNdiDL7sm-be%3DqVA%40mail.gmail.com
>>> <https://groups.google.com/a/chromium.org/d/msgid/blink-dev/CAOMQ%2Bw_tGRNHZe40U3i67XLWbsXdkzRTisdNdiDL7sm-be%3DqVA%40mail.gmail.com?utm_medium=email&utm_source=footer>
>>> .
>>>
>> --
>> You received this message because you are subscribed to the Google Groups
>> "blink-dev" group.
>> To unsubscribe from this group and stop receiving emails from it, send an
>> email to [email protected].
>>
>> To view this discussion visit
>> https://groups.google.com/a/chromium.org/d/msgid/blink-dev/CAEmk%3DMZ0OKvD21KgsuPrPVoSMXG3DASLRa30cP7Tsi%2BvedgL3Q%40mail.gmail.com
>> <https://groups.google.com/a/chromium.org/d/msgid/blink-dev/CAEmk%3DMZ0OKvD21KgsuPrPVoSMXG3DASLRa30cP7Tsi%2BvedgL3Q%40mail.gmail.com?utm_medium=email&utm_source=footer>
>> .
>>
>>

-- 
You received this message because you are subscribed to the Google Groups 
"blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/chromium.org/d/msgid/blink-dev/CACrnVjEpuYkpmMgCt%3Dz-QC7h339qRwUBGGh3-L52BY1j3ynHeg%40mail.gmail.com.

Reply via email to