Directus Logo
  • The Data Engine and Studio
    • Connect
      Generate REST and GraphQL APIs instantly
    • Explore
      Browse and filter data in custom layouts
    • Editor
      Create and manage data in custom forms
    • Files
      Store and transform all your digital assets
    • Auth
      Protect your data with granular access control
    • Insights
      Visualize data within custom dashboards
    • Automate
      An automation builder for your data
    • Realtime
      Keep your data in sync with WebSockets
    Extend Your Toolkit
    Directus Marketplace

    Directus Marketplace

    Customize your data experience with extensions.

  • Build powerful apps and tools
    • Headless CMS
      Manage and deliver digital experience content
    • Backend-as-a-Service
      Simplify backend operations and scale
    • Product Management (PIM)
      A single source of truth for products
    • 100+ More Things To Build
      Looking for inspiration? Look no further
    • Startups
      Build fast, scale faster
    • Enterprise
      Secure, scalable composable architecture
    • Agencies
      Enhance your productivity and agency offerings
    • Government
      Dual-use platform for government applications
    Focus on the frontend
    Directus Cloud

    Directus Cloud

    Convenience and scalability without the stress.

  • Technical resources
    • Directus Docs
      Documentation on set-up and using Directus
    • API Reference
      Dynamic REST and GraphQL API docs
    • Tutorials and Guides
      Our developer blog for specific use cases
    • Quickstart Guide
      Get up and running quickly
    • Roadmap
      See what's on our product roadmap
    • Security
      Our commitment to security and compliance
    • GitHub
      Visit our repo on GitHub
    • Docker Hub
      Visit the official Directus Docker hub
    Open Source
    Visit our GitHub

    Visit our GitHub

    We're committed to the open source community.

  • Learning Center
    • Blog
      Read our latest articles and guides
    • Success Stories
      Case studies and success stories
    • Community
      Join our 10k member Discord community.
    • Events & Meetups
      See upcoming events and in-person meetups
    • About Us
      Learn more about Directus and the team
    • The Wall of Love
      See what others are saying about us
    • Contact
      Have a general inquiry or question for us?
    • Support
      Reach out to Directus support
    Watch Directus TV
    Directus TV
    Video

    Directus TV

    Go down the rabbit hole with hours of original video content from our team.

  • Pricing
Get DemoGet Started
GitHub logo25,762
Back
news
Friday, October 27, 2023

Announcing the Directus Secure Extensions Framework

Learn about our new sandbox for extensions which emphasize control and security.
Announcing the Directus Secure Extensions Framework

Designing a marketplace with user-contributed content is no small feat. On top of security, consistency, and tooling, it's super important for us to be confident that the way we ask you to build extensions will stay the same for many Directus versions to come. 

Over the last year, we've laid lots of groundwork towards this goal - the Directus Extensions SDK which helps scaffold and build extensions, being able to install extensions via npm or external storage locations, a robust and flexible metadata structure, and several other changes to help you build great extensions and ensure we can run them reliably. 

Right now, we really leave it to Directus project admins to understand the security implications of installed extensions. Given that Directus touches your database and asset storage, we know there's a need to do better, especially in a future where users installing extensions may not also be managing infrastructure. 

Today, we're announcing what we believe is the last part of the foundational work required to build a marketplace - the Secure Extensions Framework. Secure Extensions will be aggressively sandboxed, with permissions needing to be requested before many actions are taken, including external web requests and database operations. 

Existing extensions not using the Secure Extensions Framework will continue to work in Directus 10.7 and beyond, but we encourage all extensions developers to adopt it as we continue work on the Directus Marketplace. 

Check out our documentation to learn more about secure extensions and, as always, if you have questions feel free to join our Discord community. 

Posted By

Esther Agbaje

Esther Agbaje

Education

Share

LinkedIn LogoTwitter LogoReddit LogoDev.to Logo

Sign up for updates 🐇

Get insights, releases, and exciting news delivered directly to your inbox once a month. No spam - we promise. 🙂

  • Directus LogoDirectus Logo

    A composable data platform to build your Headless CMS, BaaS, and more. 

  • Solutions
    • Headless CMS
    • Backend-as-a-Service
    • Product Information
    • 100+ Things to Build
  • Resources
    • Documentation
    • Guides
    • Community
    • Release Notes
  • Support
    • Issue Tracker
    • Feature Requests
    • Community Chat
    • Cloud Dashboard
  • Organization
    • About
    • Careers
    • Brand Assets
    • Contact
©2024 Monospace Inc
  • Cloud Policies
  • License
  • Terms
  • Privacy
  • github
  • discord
  • youtube
  • docker
  • npm
  • x
  • mastodon
  • linkedin