{"id":13026,"date":"2024-04-07T21:08:33","date_gmt":"2024-04-07T21:08:33","guid":{"rendered":"https:\/\/www.fhug.org.uk\/kb\/?post_type=kb_article&#038;p=13026"},"modified":"2024-04-07T21:08:33","modified_gmt":"2024-04-07T21:08:33","slug":"privacy-and-security-standards-for-published-plugins","status":"publish","type":"kb_article","link":"https:\/\/www.fhug.org.uk\/kb\/kb-article\/privacy-and-security-standards-for-published-plugins\/","title":{"rendered":"Privacy and Security Standards for Published Plugins"},"content":{"rendered":"<h2>Family Historian Plugins<\/h2>\n<p>Family Historian plugins are a powerful tool for ordinary users to create and share additional functionality for processing user data. However, this also creates the potential for plugins to corrupt that data due to either the user misunderstanding what the plugin does or from a coding error by the plugin author.<\/p>\n<p>Authors creating plugins for their own personal use can of course structure them as they wish. However, plugins made available to other users either via the Family Historian Plugin Store or via the FHUG forum must comply with a minimum set of standards designed to protect the integrity and privacy of user data and minimise the risk of accidental data loss or system corruption.<\/p>\n<p>It is intended that these standards are self-policing, and will not be proactively checked by either Plugin Store or FHUG admin. However, new plugins or revisions to existing plugins that are found to breach the standards may be subject to either required revision or removal.<\/p>\n<h2>Plugin Functions and Actions<\/h2>\n<ol>\n<li>Plugins may read the Windows Registry without restriction. They must not modify the Registry, apart from the two specific Family Historian keys, described in <a href=\"https:\/\/www.fhug.org.uk\/kb\/kb-article\/understanding-the-scope-of-features\/\" target=\"_blank\" rel=\"noopener\">Understanding the Scope of Features<\/a>, and then only if essential to the stated plugin function, such as restoring a backup of user settings.<\/li>\n<li>Where a plugin makes a change to user data or files that cannot be reversed by selecting <a href=\"#!\" class=\"cs_tooltip\" fhugtt=\"This is the menu across the top of the main Family Historian windows. The &gt; denotes a submenu\">Edit&nbsp&gt;&nbspUndo&nbspPlugin&nbspUpdates<\/a> from the main Family Historian menu, this should proceed only after requesting confirmation from the user. The confirmation message should describe what the plugin is about to do in non-technical user language, and what the potential consequences of that action are. Typically, this would arise from any change to a file other than to the project GEDCOM file made through FH API, such as Media files or Family Historian settings files (Fact Sets, Source Template Definitions, etc). Changes to the plugin\u2019s own settings data do not require specific user confirmation.<\/li>\n<li>Plugins should not make changes to user files that make them unusable without a subsequent step to complete the action, such as breaking the link between the file contents and its file name extension, to prevent corruption if the subsequent step fails.<\/li>\n<li>Plugins must not download any executable code such as Lua libraries, scripts written in any other programming language (including batch files\/command scripts), or executable files. Non-executable files (typically documents, such as help files) may be downloaded if essential to the stated action of the plugin, documented, and proceeds only after the user has confirmed consent. (Plugins written for versions of Family Historian prior to version 7 may download Lua libraries from the Family Historian website only).<br \/>\nPlugins may generate and execute text scripts (including batch files\/command scripts) necessary to fulfil their function.<\/li>\n<li>Plugins may upload user data to a published and publicly available API if essential to the stated action of the plugin (for example, a list of places uploaded to a mapping service), but only after the user has given specific consent. The process for requesting consent must include a link to the API website, including their privacy policy.<\/li>\n<li>Where a plugin provides links to relevant external websites, such as more detailed help information, a family tree site, etc., these must be clearly labelled as such in the user interface.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n","protected":false},"template":"","fh_version":[14,15,739],"skill_level":[18,17],"topic":[73],"class_list":["post-13026","kb_article","type-kb_article","status-publish","hentry","fh_version-v5","fh_version-v6","fh_version-v7","skill_level-advanced","skill_level-intermediate","topic-writing-plugins"],"_links":{"self":[{"href":"https:\/\/www.fhug.org.uk\/kb\/wp-json\/wp\/v2\/kb_article\/13026","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.fhug.org.uk\/kb\/wp-json\/wp\/v2\/kb_article"}],"about":[{"href":"https:\/\/www.fhug.org.uk\/kb\/wp-json\/wp\/v2\/types\/kb_article"}],"wp:attachment":[{"href":"https:\/\/www.fhug.org.uk\/kb\/wp-json\/wp\/v2\/media?parent=13026"}],"wp:term":[{"taxonomy":"fh_version","embeddable":true,"href":"https:\/\/www.fhug.org.uk\/kb\/wp-json\/wp\/v2\/fh_version?post=13026"},{"taxonomy":"skill_level","embeddable":true,"href":"https:\/\/www.fhug.org.uk\/kb\/wp-json\/wp\/v2\/skill_level?post=13026"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.fhug.org.uk\/kb\/wp-json\/wp\/v2\/topic?post=13026"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}