diff --git a/SECURITY.md b/SECURITY.md
index b6ed572..ff65db2 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -4,8 +4,8 @@ This repository is `learning.nyuchi.com`: a static Astro site, served by
Vercel, and the home of the Toddle Enhancement Extension.
The extension's own security model, how it is tested, and its adversarial
-reviews of 1 October 2026 (0.8.2) and 6 October 2026 (0.8.4, before it is
-published), with their findings and the limits of code that runs in Toddle's
+reviews of 1 October 2026 (0.8.2) and 6 October 2026 (0.8.4, a test build;
+its fixes reach schools in 0.9.0), with their findings and the limits of code that runs in Toddle's
page, are published for schools at
[learning.nyuchi.com/legal/security](https://learning.nyuchi.com/legal/security).
The vulnerability disclosure policy, covering this site, the extension and the
diff --git a/public/llms.txt b/public/llms.txt
index cb13946..57985b7 100644
--- a/public/llms.txt
+++ b/public/llms.txt
@@ -44,8 +44,9 @@ community-based platforms. Nyuchi Web Services is its development division.
course, room and every teacher with their display title and email; the
teachers can be emailed together. Message buttons open Toddle's own chat;
the extension sends no message itself. From version 0.9.0 the flag switch,
- the student sidebar and the home page's additions run in the extension's
- own isolated world, drawn in closed shadow roots that no script on
+ the student sidebar, the home page's additions, the gradebook's toolbar
+ and controls, and the Attendance dashboard's details run in the
+ extension's own isolated world, drawn in closed shadow roots that no script on
Toddle's page can read or click into. On the Attendance dashboard's Students
tab, each student's year group and current class and teacher appear under
their name, and the current block's column is outlined. It reads Toddle in
@@ -56,7 +57,7 @@ community-based platforms. Nyuchi Web Services is its development division.
primary teacher names; the Attendance dashboard's year groups and the
teacher of each student's current class; and, in the sidebar, the
student's details, contacts, classes, today's timetable and attendance,
- and their flags when they are shown. It notes the sign-in headers and
+ and their flags. It notes the sign-in headers and
academic year from Toddle's own requests only to ask Toddle as the
teacher; it never asks for a password. Nothing it reads leaves the browser
except back to Toddle; it transmits nothing from Toddle to anyone else: no
@@ -67,8 +68,10 @@ community-based platforms. Nyuchi Web Services is its development division.
email domain), which is compared with the signed-in Toddle account inside
the browser only. An organisation licence is one key for the school's
email domain: anyone signed in to Toddle with an address at that domain is
- covered. The sidebar asks Toddle for a student's flags each time it opens,
- and keeps them only while it is open. Apart
+ covered. From version 0.9.0 the sidebar asks Toddle for a student's
+ active flags each time it opens, and keeps them only while it is open; in
+ version 0.8.2, while flags are hidden, it asks only when someone presses
+ its eye button. Apart
from Toddle, it has two outside connections, neither carrying Toddle
data. (1) Opt-in feedback: the toolbar menu's "Send feedback" form, which, only when the person presses
Send, sends what they typed (topic, message, and an email only if they
diff --git a/src/pages/legal/security.astro b/src/pages/legal/security.astro
index f77fde4..6685ce4 100644
--- a/src/pages/legal/security.astro
+++ b/src/pages/legal/security.astro
@@ -60,7 +60,7 @@ const glance = [
},
{
label: "Reviewed",
- value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version} before it is published.`,
+ value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, whose fixes reach schools in 0.9.0.`,
},
];
@@ -365,15 +365,15 @@ const severityClass: Record
The extension is being rebuilt so that as little of it as possible runs where
Toddle's own scripts run. From version {security.next}, the flag switch, the student
- sidebar with a class's teachers, and the home page's My classes option and teacher
- names run in the extension's own isolated part of the browser. What they draw on
+ sidebar with a class's teachers, the home page's My classes option and teacher
+ names, the gradebook's toolbar and controls, and the Attendance dashboard's details
+ run in the extension's own isolated part of the browser. What they draw on
Toddle's pages sits inside closed shadow roots, which no script on Toddle's page can
read or click into, and whether each one runs is decided by the extension's own
switches and licence, never by Toddle's page. What only Toddle's page holds (who was
clicked, the course list as it loads, Toddle's chat and icons) is read by small parts
with no interface of their own, which talk to the extension on private channels set
- up before Toddle's own scripts run. The gradebook and the Attendance dashboard are
- moving the same way.
+ up before Toddle's own scripts run.
Protections inside the page
@@ -511,7 +511,8 @@ const severityClass: Record
- The extension no longer hides Toddle's own flags: they stay where Toddle puts - them, with their links and documents in Toddle's student popover. Concealing - them is your choice, off until you switch it on. {flags.reveal} + From version {extensionVersions.next}, the extension no longer hides Toddle's own + flags: they stay where Toddle puts them, with their links and documents in Toddle's student popover. Concealing + them is your choice: a new install starts with flags shown, and if you are + updating from 0.8.2, where flags were hidden by default, or you had hidden them + yourself, they stay concealed until you show them. {flags.reveal}