Skip to content

release: staging to main (2026-10-06) - #69

Draft
bryanfawcett wants to merge 5 commits into
mainfrom
release/2026-10-06
Draft

bryanfawcett wants to merge 5 commits into
mainfrom
release/2026-10-06

Conversation

@bryanfawcett

Copy link
Copy Markdown
Member

Release of staging to main. The branch is main + staging's five commits (main is an ancestor of staging, so the tree equals staging exactly).

Review and verification are recorded in a comment below.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq

bryanfawcett and others added 5 commits October 4, 2026 20:27
Every merge into `staging` (the live beta) is released as the next patch
under the org versioning policy (nyuchi/.github#80), through the pinned
reusable-staging-release.yml. The build workflow now also runs on pushes
to `staging`, so the beta branch carries the same checks as master.


Claude-Session: https://claude.ai/code/session_017T4NxM5wbhJ3LjHt7bnuwr

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* chore: the default branch is main

The default branch was renamed from master to main on 2026-10-04. Point
the build trigger and the README at it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017T4NxM5wbhJ3LjHt7bnuwr

* ci: build on pushes to main

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017T4NxM5wbhJ3LjHt7bnuwr

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…claim matches its code (#66)

* docs(legal): every claim about the extension matches its code, for 0.8.2 and 0.8.4

Checked against the extension at 75876d4 (docs/toddle-data-fields.md, the
security reviews, SECURITY.md, licence.js, background.js and the code).

- Flags: from 0.8.4 they are shown as Toddle shows them and the free switch
  hides them everywhere; before 0.8.4 they were hidden by default. Unless
  flags are hidden, the sidebar asks Toddle for them each time it opens.
- Memory: answers stay in the tab until it is closed or reloaded, reused
  for at most 5 minutes (2 for a student's day); never written to storage.
- Storage: licenceCheck and licenceViewer in the extension's storage, and
  the four values on Toddle's site, each described. Drops a "message button
  style" value the code does not have.
- Switches: adds gradebook tools and the Attendance dashboard's details.
- Licence keys may, not must, name who they are for.
- Reads: gradebook, home page, profile page and Attendance dashboard, plus
  the sign-in headers and academic year noted from Toddle's own requests.
- What leaves the device, listed exactly, student photos included.
- Security page: the review of 6 October 2026 (findings 13 to 16) and what
  code inside Toddle's page cannot promise; says which versions it covers.
- Version facts in one place (extensionVersions); dated 6 October 2026.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq

* docs(legal): privacy rests on Zimbabwe's Act and the GDPR; fix missing spaces

- The privacy policy names the two laws Nyuchi holds itself to: Zimbabwe's
  Cyber and Data Protection Act [Chapter 12:07], and the EU and UK GDPR,
  applied to everyone. "The law we follow" names POTRAZ, says where data goes
  and how transfers out of the EU and UK are covered. The rights section
  lists each right, the one-month answer and where to complain (POTRAZ, the
  ICO, or an EU authority). Each legal basis carries its GDPR article.
- Breaches go to POTRAZ within 24 hours (Zimbabwe's Act), and to an EU or
  UK regulator within 72 where the GDPR requires it (privacy and data pages).
- Student privacy names both laws. Singapore's PDPA is no longer named, in
  the pages or the consent notes. The facts live once, in `dataProtection`.
- compressHTML off: Astro's compression dropped the space where a line break
  sat next to an inline tag ("Applies to<strong>…"), about 90 times across
  the legal and product pages. Now none; CSP hashes unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq

---------

Co-authored-by: Bryan Fawcett <noreply@anthropic.com>
…oncealed, not hidden (#67)

* docs: the extension page and legal pages describe 0.9.0, with flags concealed, not hidden

The pages described 0.8.4 as the next release and said the flag switch
hides flags. Patches are now test releases that do not go to the Chrome Web
Store, so the next release teachers get is 0.9.0, and from it the extension
no longer hides Toddle's own flags: a teacher can conceal them for a shared
screen.

- Flags, said once in `flags` (src/data/legal.ts): "conceal" and "flag
  visibility", never "hide"; "Show flags" in the sidebar for one student;
  concealing is a screen, not a lock. A test fails on "hide flags".
- The rebuild in closed shadow roots, the student sidebar's timetable,
  email and admin-portal changes, a class's teachers by email, and My
  classes switching at once.
- For schools: the rollout steps and the organisation key on the extension
  page, a help centre link, and the data schema, described and on request.
- Data handling: the licence server keeps a hash of each key, not the key.
- The Zimbabwe CDPA and GDPR framing is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq

* fix: sitemap lastmod is an ISO string, and source-map-js 1.2.2 for GHSA-68fv-2mgg-jv7q

- astro.config.mjs: the sitemap's serialize hook set `lastmod` to a Date,
  but a sitemap item's `lastmod` is a string (TS2322 in `npm run lint`).
  It is now `new Date().toISOString()`; the sitemap output is the same
  ISO 8601 timestamp.
- package-lock.json: source-map-js 1.2.1 → 1.2.2, the patched release for
  GHSA-68fv-2mgg-jv7q (high), which failed "Audit what ships". Every
  dependent's range already allows 1.2.2, so it is `npm update
  source-map-js`, run with the repo's npm (11.12.1); no override needed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq

* docs: the newest patch is 0.8.9

Extension PR #38 (My classes switches at once; docs/data-schema.md) merged
into staging and shipped in the v0.8.9 patch.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq

---------

Co-authored-by: Bryan Fawcett <noreply@anthropic.com>
…s it (#68)

* feat: a public Releases page for the extension; the terms say who owns it

Releases need a public home: the extension's repository is private and its
GitHub releases are internal test builds.

- /toddle-enhancement-extension/releases: each version's notes in plain
  words for teachers, newest first, from the extension's changelog. 0.9.0
  is coming soon to the Chrome Web Store; 0.8.2, 0.8.1, 0.8.0, 0.7.x and the
  early builds follow, condensed; 0.8.3 to 0.8.13, test builds for pilot
  schools, are one line. Every version has the anchor #v<version> for the
  extension's menu. No downloads, no GitHub links. Data in
  src/data/releases.ts. Linked from the extension page, the footer and
  llms.txt; in the sitemap.
- Terms: the extension and its code belong to Nyuchi Web Services, all
  rights reserved, not open source; a licence grants use, not ownership; no
  copying, modifying, reusing or redistributing its code in another product
  or service without written permission. Reading the code stays welcome;
  building a competing product stays forbidden. Said once in `ownership`.
- Flags facts as 0.9.0 ships them (grey, no colour; 0.8.2 updaters
  concealed); the newest test build is 0.8.13.
- Tests: the releases page's anchors, no downloads or GitHub links, and the
  organisation price is US$149.99 everywhere.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq

* @bundu/ui 0.5.0; the site's code is proprietary

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq

---------

Co-authored-by: Bryan Fawcett <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
learning Ready Ready Preview Oct 6, 2026 7:49am UTC

Request Review

@bryanfawcett

Copy link
Copy Markdown
Member Author

Held (owner decision, 2026-10-06): this release waits until the Toddle Enhancement Extension 0.9.0 ships. That is tracked in nyuchi/toddle-enhancement-extension#42; there is no extension release to main or the Chrome Web Store until the rebuild is complete.

Why: staging's product page describes 0.9.0 as current. The live page (main) correctly says 0.8.2 hides flags by default. Staging says "The extension never hides Toddle's own student flags", "no longer hides Toddle's own flags" and "Concealing them is your choice, off until you switch it on", with only a later note that this describes 0.9.0. The structured-data feature list says "never hides Toddle's own flags". The legal pages (data, privacy, security, student-privacy) describe both versions ("From version 0.9.0 … In version 0.8.2, on the Chrome Web Store today …"), and the releases page marks 0.9.0 "Coming soon".

Review record: /code-review on this diff found 4 copy inconsistencies (no blocking bugs). They are fixed in #70, which has a clean re-review and green CI, and is left for the owner. Checks on the release tree: price US$149.99 everywhere; "licence" is always the noun; the CSP covers 5 inline scripts across 14 pages; no broken internal links or anchors; 96/96 tests pass.

🤖 Generated with Claude Code

@bryanfawcett
bryanfawcett marked this pull request as draft October 6, 2026 08:15

This branch was successfully deployed

1 active deployment
Preview — aca358c8 Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant