Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ name: build
on:
pull_request:
push:
branches: [master]
branches: [main, staging]

permissions:
contents: read
Expand Down
25 changes: 25 additions & 0 deletions .github/workflows/staging-version.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
# Versioning policy (nyuchi/.github#80): every merge into `staging` is
# released as the next PATCH, tagged on the merged commit.
name: Staging version

on:
push:
branches: [staging]
workflow_dispatch:
inputs:
bump:
description: Override the bump (major is only ever manual).
type: choice
options: [patch, minor, major]
default: patch

permissions:
contents: read

jobs:
version:
uses: nyuchi/.github/.github/workflows/reusable-staging-release.yml@924e5b4d0983d31379aedbec02b990793f29c792 # main, 2026-10-04
with:
bump: ${{ inputs.bump || '' }}
permissions:
contents: write
95 changes: 95 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,103 @@

## Unreleased

### Added

- **A Releases page for the extension**, at
`/toddle-enhancement-extension/releases`: what changed in each version,
in plain words for teachers, newest first. 0.9.0 is "Coming soon to the
Chrome Web Store"; 0.8.2, 0.8.1, 0.8.0, 0.7.x and the early builds follow,
condensed. Versions 0.8.3 to 0.8.13, test builds for schools piloting the
extension, are said in one line: their changes arrive together in 0.9.0.
Each version has the anchor `#v<version>`, which the extension's menu will
link to. No downloads and no GitHub links: the extension's repository is
private, and teachers install from the Chrome Web Store. The notes live in
`src/data/releases.ts`, so adding a release is one edit. Linked from the
extension page, the footer and llms.txt, and in the sitemap.

### Changed

- **@bundu/ui 0.5.0** (was 0.1.1): the kit's updated tokens. The page
background is a cooler, neutral off-white; layout, type, buttons and the
Nyuchi brand colours are unchanged. Every check and test passes as before.
- **The site's code is proprietary**, all rights reserved, with a LICENSE
file saying so (it had none). Not open source.

- **The terms say who owns the extension.** A new "Who owns the extension"
section: the extension and its code belong to Nyuchi Web Services, part
of Nyuchi Africa (Private) Limited, all rights reserved, and it is not
open source. A licence grants use, not ownership. Its code may not be
copied, modified, reused or redistributed, in whole or in part, in another
product or service without written permission. Reading the code to check
what it does stays welcome, and building a competing product stays
forbidden. Said once, in `ownership` (`src/data/legal.ts`), and repeated on
the extension page and in llms.txt.
- **Student flags, as 0.9.0 ships them:** a concealed flag is a grey smudge
with no colour, nothing on the page brings it back, and a teacher updating
from 0.8.2 has flags concealed.
- **The extension page and legal pages describe 0.9.0, the next Chrome Web
Store release**, and say where 0.8.2, on the store today, differs. Patches
(0.8.3 to 0.8.13) are test releases that do not go to the store, so
`extensionVersions.next` is now 0.9.0, not 0.8.4.
- Student flags: the extension no longer hides Toddle's own flags. A
teacher can conceal them for a shared screen with the free switch, and
"Show flags" in the sidebar shows one student's. The wording is
"conceal" and "flag visibility", said once in `flags`
(`src/data/legal.ts`); a test fails on "hide flags" on the extension
page, the home page and in llms.txt. The sidebar asks Toddle for a
student's flags each time it opens. The value on Toddle's site is
`tee-blur-flags` (`gbx-hide-flags` in 0.8.2).
- The rebuild: the flag switch, the student sidebar and the home page's
additions run in the extension's isolated world, in closed shadow roots
(product page, Security page, llms.txt). The Security page adds the home
page channel's limit.
- The student sidebar: today's timetable as its own part, the student's
email, a class's teachers to email at once, and stepping aside in
Toddle's admin portal. My classes switches on and off at once.
- For schools: the Admin console, Group Policy, Intune and macOS steps,
the organisation key pasted in once by each teacher, and allowing
`licences.nyuchi.dev`, summarised on the extension page; the full guide
on request. A link to the help centre's "How to use" collection.
- The data schema (the extension's `docs/data-schema.md`) is described on
the data handling page and the extension page, available on request.
- Data handling: the licence server keeps a SHA-256 of each key, never
the key itself, and the school's email domains for an organisation key.
- The second security review was of 0.8.4, a test release; its fixes are
in 0.9.0.
- **The privacy policy rests on two laws: Zimbabwe's Cyber and Data
Protection Act [Chapter 12:07] and the EU and UK GDPR**, applied to everyone.
A new "The law we follow" section names POTRAZ as Zimbabwe's regulator, says
where data goes and how transfers out of the EU and UK are covered, and the
rights section lists each right, the one-month answer and where to complain
(POTRAZ, the ICO, or an EU authority). Each legal basis carries its GDPR
article. A breach goes to POTRAZ within 24 hours, as Zimbabwe's Act requires,
and to an EU or UK regulator within 72 where the GDPR requires it. Singapore's
PDPA is no longer named. The facts live once, in `dataProtection`
(`src/data/legal.ts`).
- **The legal pages match the extension's code, for 0.8.2 and 0.8.4**, and
are dated 6 October 2026. Checked against the extension's data schema
(`docs/toddle-data-fields.md`) and its code:
- Student flags: from 0.8.4 they are shown as Toddle shows them, and the
free switch hides them everywhere; versions before 0.8.4 hid them by
default. Unless flags are hidden, the sidebar asks Toddle for a
student's flags each time it opens.
- Memory: answers stay in the tab's memory until it is closed or
reloaded, reused for at most 5 minutes (2 for a student's day). Not
"a few minutes, then discarded".
- Storage: every key, named — the last revocation check and the Toddle
account's email in the extension's storage, and the four values on
Toddle's site (`tee-settings`, `gbx-hide-flags`, `tee-course-view`,
`tee-academic-year`). The "style of Toddle's message button" value it
once listed does not exist.
- Every switch, including gradebook tools and the Attendance dashboard's
student details.
- Licence keys may, not must, name who they are for.
- What each feature reads (gradebook, home page, profile page, Attendance
dashboard, sidebar), and the sign-in headers and academic year noted
from Toddle's own requests.
- Exactly what leaves the device, student photos included.
- The Security page covers the adversarial review of 6 October 2026
(findings 13 to 16) and what code inside Toddle's page cannot promise.
- **The audit sets one advisory aside, by ID, until 2026-11-03** (CI only).
GHSA-ch52-4w7c-c8xp in `http-cache-semantics` has no patched release, and
astro 7.3.5 uses the package only to cache remote images during
Expand Down
17 changes: 17 additions & 0 deletions LICENSE
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
Copyright (c) 2026 Nyuchi Web Services. All rights reserved.

This website, learning.nyuchi.com, its source code, content, designs and
other materials in this repository (the "Software") are the property of
Nyuchi Web Services and are protected by copyright and other intellectual
property laws. The Software is proprietary. It is not open source.

No licence or right to copy, modify, merge, publish, distribute,
sublicense, sell, deploy, or otherwise reuse the Software, in whole or in
part, is granted without the prior written permission of Nyuchi Web
Services. Contact: support@nyuchi.com.

Third-party packages it depends on keep their own licences.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
![Astro](https://img.shields.io/badge/Astro-7-BC52EE?style=flat-square&logo=astro&logoColor=white)
![Vercel](https://img.shields.io/badge/Vercel-deployed-000000?style=flat-square&logo=vercel&logoColor=white)

**Version:** 3.0.0 | **Live:** [learning.nyuchi.com](https://learning.nyuchi.com) | **Default branch:** `master` | **Deploy:** Vercel
**Version:** 3.0.0 | **Live:** [learning.nyuchi.com](https://learning.nyuchi.com) | **Default branch:** `main` | **Deploy:** Vercel

---

Expand Down Expand Up @@ -54,7 +54,7 @@ every Nyuchi surface at once.

## Hosting

Vercel, from `master`. The site is fully static — every page is known at build
Vercel, from `main`. The site is fully static — every page is known at build
time, so nothing renders per request.

Response headers, including the CSP, are declared in `vercel.json`.
Expand Down
6 changes: 4 additions & 2 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,10 @@
This repository is `learning.nyuchi.com`: a static Astro site, served by
Vercel, and the home of the Toddle Enhancement Extension.

The extension's own security model, how it is tested and its independent
adversarial review are published for schools at
The extension's own security model, how it is tested, and its adversarial
reviews of 1 October 2026 (0.8.2) and 6 October 2026 (0.8.4, before it is
published), with their findings and the limits of code that runs in Toddle's
page, are published for schools at
[learning.nyuchi.com/legal/security](https://learning.nyuchi.com/legal/security).
The vulnerability disclosure policy, covering this site, the extension and the
licence server, is at
Expand Down
7 changes: 6 additions & 1 deletion astro.config.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,10 @@ import tailwindcss from "@tailwindcss/vite";

export default defineConfig({
site: "https://learning.nyuchi.com",
/* Astro's HTML compression drops the space where a line break sits between
text and an inline tag ("Applies to<strong>…"), across the legal pages.
The pages are small; correct words matter more than a few bytes. */
compressHTML: false,
adapter: vercel(),

// Fully static: every page is known at build time, so there is nothing to
Expand All @@ -31,7 +35,8 @@ export default defineConfig({
*/
serialize(item) {
item.url = item.url.replace(/(.+)\/$/, "$1");
item.lastmod = new Date();
// The sitemap item takes an ISO 8601 string, not a Date.
item.lastmod = new Date().toISOString();
return item;
},
}),
Expand Down
32 changes: 21 additions & 11 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

3 changes: 2 additions & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
"name": "nyuchi-learning",
"version": "3.0.0",
"private": true,
"license": "UNLICENSED",
"type": "module",
"description": "learning.nyuchi.com — the Nyuchi Learning surface and the home of the Toddle Enhancement Extension.",
"scripts": {
Expand All @@ -23,7 +24,7 @@
"ci:check": "astro check && vp fmt --check"
},
"dependencies": {
"@bundu/ui": "^0.1.1",
"@bundu/ui": "^0.5.0",
"astro": "^7.3.5"
},
"devDependencies": {
Expand Down
Loading
Loading