Files
jhonny-editor/code/docs/recommendations/2026-08-18/12-uxp-auth-header.md
T
João Henrique b541f502ba feat: initial commit - Jhonny Editor
- Adicionado estrutura completa do projeto
- Configurado MCP server para Premiere Pro
- Adicionado documentação e skills
- Configurado Gitignore para o projeto
2026-09-08 09:59:31 -04:00

1.1 KiB
Executable File

Recommendation 12: remove UXP tokens from URLs

Evidence

The loopback bridge authenticates with a token query parameter. URLs are more likely than headers to appear in diagnostics, proxy logs, screenshots, or error strings. Adobe UXP WebSocket access remains permission-gated by the manifest and runtime URL checks.

Proposed improvement

Move the secret to a WebSocket subprotocol or supported authorization header while retaining constant-time comparison, loopback binding, exact path checks, and a short documented compatibility window for query authentication. Redact both forms everywhere.

Acceptance

  • New panel connections contain no secret in the URL.
  • Missing, duplicate, malformed, and wrong credentials fail before upgrade.
  • Logs, telemetry, status UI, and errors never contain credential material.
  • Compatibility mode is opt-in, warned, tested, and assigned a removal version.

The chosen mechanism must be proven in Premiere 26.3 UXP, not only browser mocks.