diff --git a/SECURITY.md b/SECURITY.md index b6ed572..ff65db2 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -4,8 +4,8 @@ This repository is `learning.nyuchi.com`: a static Astro site, served by Vercel, and the home of the Toddle Enhancement Extension. The extension's own security model, how it is tested, and its adversarial -reviews of 1 October 2026 (0.8.2) and 6 October 2026 (0.8.4, before it is -published), with their findings and the limits of code that runs in Toddle's +reviews of 1 October 2026 (0.8.2) and 6 October 2026 (0.8.4, a test build; +its fixes reach schools in 0.9.0), with their findings and the limits of code that runs in Toddle's page, are published for schools at [learning.nyuchi.com/legal/security](https://learning.nyuchi.com/legal/security). The vulnerability disclosure policy, covering this site, the extension and the diff --git a/public/llms.txt b/public/llms.txt index cb13946..57985b7 100644 --- a/public/llms.txt +++ b/public/llms.txt @@ -44,8 +44,9 @@ community-based platforms. Nyuchi Web Services is its development division. course, room and every teacher with their display title and email; the teachers can be emailed together. Message buttons open Toddle's own chat; the extension sends no message itself. From version 0.9.0 the flag switch, - the student sidebar and the home page's additions run in the extension's - own isolated world, drawn in closed shadow roots that no script on + the student sidebar, the home page's additions, the gradebook's toolbar + and controls, and the Attendance dashboard's details run in the + extension's own isolated world, drawn in closed shadow roots that no script on Toddle's page can read or click into. On the Attendance dashboard's Students tab, each student's year group and current class and teacher appear under their name, and the current block's column is outlined. It reads Toddle in @@ -56,7 +57,7 @@ community-based platforms. Nyuchi Web Services is its development division. primary teacher names; the Attendance dashboard's year groups and the teacher of each student's current class; and, in the sidebar, the student's details, contacts, classes, today's timetable and attendance, - and their flags when they are shown. It notes the sign-in headers and + and their flags. It notes the sign-in headers and academic year from Toddle's own requests only to ask Toddle as the teacher; it never asks for a password. Nothing it reads leaves the browser except back to Toddle; it transmits nothing from Toddle to anyone else: no @@ -67,8 +68,10 @@ community-based platforms. Nyuchi Web Services is its development division. email domain), which is compared with the signed-in Toddle account inside the browser only. An organisation licence is one key for the school's email domain: anyone signed in to Toddle with an address at that domain is - covered. The sidebar asks Toddle for a student's flags each time it opens, - and keeps them only while it is open. Apart + covered. From version 0.9.0 the sidebar asks Toddle for a student's + active flags each time it opens, and keeps them only while it is open; in + version 0.8.2, while flags are hidden, it asks only when someone presses + its eye button. Apart from Toddle, it has two outside connections, neither carrying Toddle data. (1) Opt-in feedback: the toolbar menu's "Send feedback" form, which, only when the person presses Send, sends what they typed (topic, message, and an email only if they diff --git a/src/pages/legal/security.astro b/src/pages/legal/security.astro index f77fde4..6685ce4 100644 --- a/src/pages/legal/security.astro +++ b/src/pages/legal/security.astro @@ -60,7 +60,7 @@ const glance = [ }, { label: "Reviewed", - value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version} before it is published.`, + value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, whose fixes reach schools in 0.9.0.`, }, ]; @@ -365,15 +365,15 @@ const severityClass: Record = {

The extension is being rebuilt so that as little of it as possible runs where Toddle's own scripts run. From version {security.next}, the flag switch, the student - sidebar with a class's teachers, and the home page's My classes option and teacher - names run in the extension's own isolated part of the browser. What they draw on + sidebar with a class's teachers, the home page's My classes option and teacher + names, the gradebook's toolbar and controls, and the Attendance dashboard's details + run in the extension's own isolated part of the browser. What they draw on Toddle's pages sits inside closed shadow roots, which no script on Toddle's page can read or click into, and whether each one runs is decided by the extension's own switches and licence, never by Toddle's page. What only Toddle's page holds (who was clicked, the course list as it loads, Toddle's chat and icons) is read by small parts with no interface of their own, which talk to the extension on private channels set - up before Toddle's own scripts run. The gradebook and the Attendance dashboard are - moving the same way. + up before Toddle's own scripts run.

Protections inside the page

@@ -511,7 +511,8 @@ const severityClass: Record = { medium-severity issues and two low (findings {secondReview.findings}). All were fixed in version {secondReview.version}, and the fixes are in every release after it, including {security.next}. None was in version {security.version}. Each later - step of the rebuild (the student sidebar, the home page) was reviewed the same way as + step of the rebuild (the student sidebar, the home page, the gradebook's toolbar and + the Attendance dashboard's details) was reviewed the same way as it was made, and what those reviews found about the page's limits is set out below.

diff --git a/src/pages/toddle-enhancement-extension.astro b/src/pages/toddle-enhancement-extension.astro index 9bc2aa9..774314b 100644 --- a/src/pages/toddle-enhancement-extension.astro +++ b/src/pages/toddle-enhancement-extension.astro @@ -177,7 +177,7 @@ const facts = [ { label: "Where it runs", value: - "Only on web.toddleapp.com. It has no access to any other site. From version 0.9.0 the flag switch, the student sidebar and the home page's additions run in the extension's own isolated part of the browser, drawn inside closed shadow roots that no script on Toddle's page can read or click into; the gradebook and the Attendance dashboard are moving the same way.", + "Only on web.toddleapp.com. It has no access to any other site. From version 0.9.0 the flag switch, the student sidebar, the home page's additions, the gradebook's toolbar and controls, and the Attendance dashboard's details run in the extension's own isolated part of the browser, drawn inside closed shadow roots that no script on Toddle's page can read or click into.", }, { label: "What it reads", @@ -380,9 +380,11 @@ const schema = [ room should not be reading over your shoulder.

- The extension no longer hides Toddle's own flags: they stay where Toddle puts - them, with their links and documents in Toddle's student popover. Concealing - them is your choice, off until you switch it on. {flags.reveal} + From version {extensionVersions.next}, the extension no longer hides Toddle's own + flags: they stay where Toddle puts them, with their links and documents in Toddle's student popover. Concealing + them is your choice: a new install starts with flags shown, and if you are + updating from 0.8.2, where flags were hidden by default, or you had hidden them + yourself, they stay concealed until you show them. {flags.reveal}