marker-io / browser-sdk

Marker.io browser SDK
MIT License
8 stars 8 forks source link

META: The SDK needs some attention #39

Open MatthewAry opened 2 weeks ago

MatthewAry commented 2 weeks ago

This SDK is basically a vehicle for marker to inject their widget script from a remote host (outside of the control of the customer) into a client application. Because of this, it's impossible to independently audit, or manage the release version, or gain helpful insights into the SDK being used.

I think that the current approach is holding marker.io back because as I dig more and more into how it works, the more uncomfortable I become about using it. Marker's SDK is no different from adding a script via CDN, except that script is a black-box and we have no control over the script's version, contents, etc. Marker could push an update that breaks our software and there would be no way to stop it with any QA processes. This needs to change.

With that said, I hope to see improvements to Marker soon!

emilevictorportenart commented 2 days ago

Thank you for your feedback, Matthew. We are planning to fix all these issues soon, we'll keep you in the loop. We have limited resources internally and are doing our best to prioritize your feedback. Thank you for your patience!