Files
jhonny-editor/code/docs/recommendations/2026-08-19-round-3/49-external-launch-policy.md
T
João Henrique b541f502ba feat: initial commit - Jhonny Editor
- Adicionado estrutura completa do projeto
- Configurado MCP server para Premiere Pro
- Adicionado documentação e skills
- Configurado Gitignore para o projeto
2026-09-08 09:59:31 -04:00

22 lines
1.1 KiB
Markdown
Executable File

# Recommendation 49: UXP external-launch policy
## Evidence
Adobe UXP requires explicit `launchProcess` manifest permissions for external schemes and file extensions, distinguishes `openPath()` from `openExternal()`, and reports user denial through return values.
- [Adobe UXP external-process recipe](https://developer.adobe.com/premiere-pro/uxp/resources/recipes/external-process)
- [Adobe Premiere UXP manifest](https://developer.adobe.com/premiere-pro/uxp/plugins/concepts/manifest/)
## Proposed improvement
If the panel adds “open export,” “reveal artifact,” or documentation links, route them through one allowlisted launch broker. Require a user gesture, canonical destination, scheme/extension policy, and explicit denial handling.
## Acceptance criteria
- Production permissions contain only reviewed schemes and extensions.
- Arguments, custom commands, UNC paths, and untrusted URLs are rejected.
- Launch failures never become export failures or success claims.
- Windows and macOS packaging tests verify the exact manifest.
This recommendation does not add process execution to the current production panel.