Streaming Hub 0.1

Plugin identity and trust

Identify an external plugin clearly and explain the trust decision to users.

Alpha

Trust

External plugins execute code in the host process. Users must be able to identify the publisher and review untrusted plugin warnings.

Official signature

Cryptographic signatures are reserved for official Streaming Hub plugins published by the project owner. External plugin authors do not receive this signature and should not present their plugin as official.

External plugin identity

Provide an accurate plugin ID, version, publisher name and author information. Keep this identity consistent between releases.

Secrets

Store credentials through supported settings mechanisms. Never include tokens in logs, manifests or diagnostic descriptions.