Repository navigation
docs(legal): every claim about the extension matches its code, for 0.8.2 and 0.8.4 - #66
Merged
Merged
Conversation
…8.2 and 0.8.4 Checked against the extension at 75876d4 (docs/toddle-data-fields.md, the security reviews, SECURITY.md, licence.js, background.js and the code). - Flags: from 0.8.4 they are shown as Toddle shows them and the free switch hides them everywhere; before 0.8.4 they were hidden by default. Unless flags are hidden, the sidebar asks Toddle for them each time it opens. - Memory: answers stay in the tab until it is closed or reloaded, reused for at most 5 minutes (2 for a student's day); never written to storage. - Storage: licenceCheck and licenceViewer in the extension's storage, and the four values on Toddle's site, each described. Drops a "message button style" value the code does not have. - Switches: adds gradebook tools and the Attendance dashboard's details. - Licence keys may, not must, name who they are for. - Reads: gradebook, home page, profile page and Attendance dashboard, plus the sign-in headers and academic year noted from Toddle's own requests. - What leaves the device, listed exactly, student photos included. - Security page: the review of 6 October 2026 (findings 13 to 16) and what code inside Toddle's page cannot promise; says which versions it covers. - Version facts in one place (extensionVersions); dated 6 October 2026. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
…g spaces
- The privacy policy names the two laws Nyuchi holds itself to: Zimbabwe's
Cyber and Data Protection Act [Chapter 12:07], and the EU and UK GDPR,
applied to everyone. "The law we follow" names POTRAZ, says where data goes
and how transfers out of the EU and UK are covered. The rights section
lists each right, the one-month answer and where to complain (POTRAZ, the
ICO, or an EU authority). Each legal basis carries its GDPR article.
- Breaches go to POTRAZ within 24 hours (Zimbabwe's Act), and to an EU or
UK regulator within 72 where the GDPR requires it (privacy and data pages).
- Student privacy names both laws. Singapore's PDPA is no longer named, in
the pages or the consent notes. The facts live once, in `dataProtection`.
- compressHTML off: Astro's compression dropped the space where a line break
sat next to an inline tag ("Applies to<strong>…"), about 90 times across
the legal and product pages. Now none; CSP hashes unchanged.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq
bryanfawcett
marked this pull request as ready for review
October 5, 2026 23:45
This was referenced Oct 6, 2026
Merged
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The legal pages now match what the Toddle Enhancement Extension's code does, checked against the extension's source and its data-fields document (
docs/toddle-data-fields.md). They describe both 0.8.2, which teachers have now (0.8.3 carries the same code), and 0.8.4, the next patch. Where the two differ, the pages say "from version 0.8.4". The version numbers live once, inextensionVersionsinsrc/data/legal.ts.What changed
Flags. From 0.8.4, flags show as Toddle shows them. The free switch hides them everywhere. Versions before 0.8.4 hid them by default. Unless flags are hidden, the sidebar asks Toddle for a student's flags each time it opens, and keeps them only while it is open.
Memory. "Held for a few minutes" is replaced by what the code does. Answers stay in the tab's memory until the tab is closed or reloaded. They are never written to storage, and are reused for at most 5 minutes (2 for a student's day).
Storage. The pages now list every stored value:
No student data is stored. The pages no longer mention a "message button style" value, which doesn't exist.
Switches. All seven are listed, including gradebook tools and student details on the Attendance dashboard.
Licence binding. A key may name who it is for. Where it does, the check runs in the browser and nothing is sent. A key naming no one works for any account until it expires (security page).
Reads. The pages now cover the gradebook, home page, profile page and Attendance dashboard reads, not just the sidebar. They also say the extension adds read-only fields to two of Toddle's own requests.
Sign-in. "Never sees your password" becomes "never asks for or stores your password". The sign-in headers stay in tab memory and go only to Toddle.
What leaves the device:
Teacher actions: CSV saved locally, mailto and tel links, and Toddle's chat.
Revocation check. "At most once a day" (a new key within 5 minutes). If the check fails, the last result stands.
Security page. It says which versions it covers. It adds the 6 October 2026 review (findings 13–16, fixed in 0.8.4 before publication) and what code inside Toddle's page cannot promise.
Terms and product page. The licence covers the Attendance dashboard's details.
Dates.
legal.updatedis 2026-10-06, and llms.txt matches.Files:
src/data/legal.ts,src/pages/legal/{privacy,data,cookies,security,student-privacy,terms,vulnerability-disclosure}.astro,src/pages/toddle-enhancement-extension.astro,public/llms.txt,SECURITY.md,CHANGELOG.md.Checks
npm run checkandnpm run ci:check: 0 errors, 0 warnings.npm run format:check: clean.npm test: build clean, 87/87 tests, CSP check passes.npm run lint: 1 error and 5 warnings, the same as onstaging. They are all in files this PR doesn't touch (astro.config.mjs,CookieBanner.astro,scripts/qa.mjs,scripts/probe-intercom-csp.mjs).Known issue, not fixed here
The built HTML drops the space where a line break sits between text and an inline tag, giving
Applies to<strong>…. This PR fixes the cases in its own new text. The rest predates it and needs a separate fix, probably in the HTML compression.Open questions
🤖 Generated with Claude Code
https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq
Generated by Claude Code