| ▲ | hobofan 4 hours ago | |||||||||||||
> A permissions system is planned I'm not sure that "Plugins will declare what they access" should be interpreted as a planned sandbox system. My (cynic) interpretation that it's an opt-in honor system, that would give a good overview about well-maintained plugins, but doesn't do anything to restrict undesired API access by malware. | ||||||||||||||
| ▲ | kepano 4 hours ago | parent [-] | |||||||||||||
We haven't shared anything about sandboxing yet. Yes, to start disclosures will be opt-in because we have to help thousands of developers with existing plugins migrate. However, a permissions system alone is not enough. For example if a user allows a plugin with network connections, it would be easy for a plugin to abuse that permission. That's why scanning the code is still necessary to give users trust in the plugin. Take a look at scorecards on the Community site, you'll see why some issues are not something a permissions system or sandboxing could catch. | ||||||||||||||
| ||||||||||||||