Streaming Hub 0.1
Plugin identity and trust
Identify an external plugin clearly and explain the trust decision to users.
AlphaTrust
External plugins execute code in the host process. Users must be able to identify the publisher and review untrusted plugin warnings.
Official signature
Cryptographic signatures are reserved for official Streaming Hub plugins published by the project owner. External plugin authors do not receive this signature and should not present their plugin as official.
External plugin identity
Provide an accurate plugin ID, version, publisher name and author information. Keep this identity consistent between releases.
Secrets
Store credentials through supported settings mechanisms. Never include tokens in logs, manifests or diagnostic descriptions.