From fbca136351a1b113d682ed81d30e314ad6bba9b5 Mon Sep 17 00:00:00 2001 From: Bryan Fawcett Date: Tue, 6 Oct 2026 15:58:34 +0800 Subject: [PATCH 1/4] docs: one account of 0.9.0 across the site (review of the release) - The extension page and the Security page say the gradebook's toolbar and the Attendance dashboard's details run in closed shadow roots from 0.9.0, as the releases page and the extension's code (rebuild steps 5 and 7) do; they no longer say these are still moving. - The second review's fixes are in 0.8.4, a test build, and reach schools in 0.9.0, not '0.8.4 before it is published'. - Concealing flags: a new install starts with flags shown; updating from 0.8.2 keeps them concealed. Not 'off until you switch it on'. - llms.txt: the sidebar asks for a student's active flags each time it opens, as legal.ts says. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq Signed-off-by: Bryan Fawcett --- SECURITY.md | 4 ++-- public/llms.txt | 2 +- src/pages/legal/security.astro | 10 +++++----- src/pages/toddle-enhancement-extension.astro | 6 ++++-- 4 files changed, 12 insertions(+), 10 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index 73d3566..76f5ecf 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -4,8 +4,8 @@ This repository is `learning.nyuchi.com`: a static Astro site, served by Vercel, and the home of the Toddle Enhancement Extension. The extension's own security model, how it is tested, and its adversarial -reviews of 1 October 2026 (0.8.2) and 6 October 2026 (0.8.4, before it is -published), with their findings and the limits of code that runs in Toddle's +reviews of 1 October 2026 (0.8.2) and 6 October 2026 (0.8.4, a test build; +its fixes reach schools in 0.9.0), with their findings and the limits of code that runs in Toddle's page, are published for schools at [learning.nyuchi.com/legal/security](https://learning.nyuchi.com/legal/security). The vulnerability disclosure policy, covering this site, the extension and the diff --git a/public/llms.txt b/public/llms.txt index bf4515b..bdbbf96 100644 --- a/public/llms.txt +++ b/public/llms.txt @@ -56,7 +56,7 @@ community-based platforms. Nyuchi Web Services is its development division. primary teacher names; the Attendance dashboard's year groups and the teacher of each student's current class; and, in the sidebar, the student's details, contacts, classes, today's timetable and attendance, - and their flags when they are shown. It notes the sign-in headers and + and their active flags, asked for each time the sidebar opens. It notes the sign-in headers and academic year from Toddle's own requests only to ask Toddle as the teacher; it never asks for a password. Nothing it reads leaves the browser except back to Toddle; it transmits nothing from Toddle to anyone else: no diff --git a/src/pages/legal/security.astro b/src/pages/legal/security.astro index 2150214..f8447f7 100644 --- a/src/pages/legal/security.astro +++ b/src/pages/legal/security.astro @@ -60,7 +60,7 @@ const glance = [ }, { label: "Reviewed", - value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version} before it is published.`, + value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, and released to schools in ${security.next}.`, }, ]; @@ -364,15 +364,15 @@ const severityClass: Record = {

The extension is being rebuilt so that as little of it as possible runs where Toddle's own scripts run. From version {security.next}, the flag switch, the student - sidebar with a class's teachers, and the home page's My classes option and teacher - names run in the extension's own isolated part of the browser. What they draw on + sidebar with a class's teachers, the home page's My classes option and teacher + names, the gradebook's toolbar and controls, and the Attendance dashboard's details + run in the extension's own isolated part of the browser. What they draw on Toddle's pages sits inside closed shadow roots, which no script on Toddle's page can read or click into, and whether each one runs is decided by the extension's own switches and licence, never by Toddle's page. What only Toddle's page holds (who was clicked, the course list as it loads, Toddle's chat and icons) is read by small parts with no interface of their own, which talk to the extension on private channels set - up before Toddle's own scripts run. The gradebook and the Attendance dashboard are - moving the same way. + up before Toddle's own scripts run.

Protections inside the page

diff --git a/src/pages/toddle-enhancement-extension.astro b/src/pages/toddle-enhancement-extension.astro index dc04194..d9cb5ad 100644 --- a/src/pages/toddle-enhancement-extension.astro +++ b/src/pages/toddle-enhancement-extension.astro @@ -177,7 +177,7 @@ const facts = [ { label: "Where it runs", value: - "Only on web.toddleapp.com. It has no access to any other site. From version 0.9.0 the flag switch, the student sidebar and the home page's additions run in the extension's own isolated part of the browser, drawn inside closed shadow roots that no script on Toddle's page can read or click into; the gradebook and the Attendance dashboard are moving the same way.", + "Only on web.toddleapp.com. It has no access to any other site. From version 0.9.0 the flag switch, the student sidebar, the home page's additions, the gradebook's toolbar and controls, and the Attendance dashboard's details run in the extension's own isolated part of the browser, drawn inside closed shadow roots that no script on Toddle's page can read or click into.", }, { label: "What it reads", @@ -382,7 +382,9 @@ const schema = [

The extension no longer hides Toddle's own flags: they stay where Toddle puts them, with their links and documents in Toddle's student popover. Concealing - them is your choice, off until you switch it on. {flags.reveal} + them is your choice: a new install starts with flags shown, and if you are + updating from 0.8.2, where flags were hidden by default, they stay concealed until + you show them. {flags.reveal}

From f7628de7d9af97fc5a85552a922bf6eca2d631d5 Mon Sep 17 00:00:00 2001 From: Bryan Fawcett Date: Tue, 6 Oct 2026 15:59:55 +0800 Subject: [PATCH 2/4] docs: re-review fixes: 0.9.0 is still to come; llms.txt matches the pages Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq Signed-off-by: Bryan Fawcett --- public/llms.txt | 10 ++++++---- src/pages/legal/security.astro | 2 +- src/pages/toddle-enhancement-extension.astro | 4 ++-- 3 files changed, 9 insertions(+), 7 deletions(-) diff --git a/public/llms.txt b/public/llms.txt index bdbbf96..3a776a9 100644 --- a/public/llms.txt +++ b/public/llms.txt @@ -44,8 +44,9 @@ community-based platforms. Nyuchi Web Services is its development division. course, room and every teacher with their display title and email; the teachers can be emailed together. Message buttons open Toddle's own chat; the extension sends no message itself. From version 0.9.0 the flag switch, - the student sidebar and the home page's additions run in the extension's - own isolated world, drawn in closed shadow roots that no script on + the student sidebar, the home page's additions, the gradebook's toolbar + and controls, and the Attendance dashboard's details run in the + extension's own isolated world, drawn in closed shadow roots that no script on Toddle's page can read or click into. On the Attendance dashboard's Students tab, each student's year group and current class and teacher appear under their name, and the current block's column is outlined. It reads Toddle in @@ -56,7 +57,7 @@ community-based platforms. Nyuchi Web Services is its development division. primary teacher names; the Attendance dashboard's year groups and the teacher of each student's current class; and, in the sidebar, the student's details, contacts, classes, today's timetable and attendance, - and their active flags, asked for each time the sidebar opens. It notes the sign-in headers and + and their active flags. It notes the sign-in headers and academic year from Toddle's own requests only to ask Toddle as the teacher; it never asks for a password. Nothing it reads leaves the browser except back to Toddle; it transmits nothing from Toddle to anyone else: no @@ -67,7 +68,8 @@ community-based platforms. Nyuchi Web Services is its development division. email domain), which is compared with the signed-in Toddle account inside the browser only. An organisation licence is one key for the school's email domain: anyone signed in to Toddle with an address at that domain is - covered. The sidebar asks Toddle for a student's flags each time it opens, + covered. From version 0.9.0 the sidebar asks Toddle for a student's flags + each time it opens, and keeps them only while it is open. Apart from Toddle, it has two outside connections, neither carrying Toddle data. (1) Opt-in feedback: the toolbar menu's "Send feedback" form, which, only when the person presses diff --git a/src/pages/legal/security.astro b/src/pages/legal/security.astro index f8447f7..2c546a3 100644 --- a/src/pages/legal/security.astro +++ b/src/pages/legal/security.astro @@ -60,7 +60,7 @@ const glance = [ }, { label: "Reviewed", - value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, and released to schools in ${security.next}.`, + value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, and to be released to schools in ${security.next}.`, }, ]; diff --git a/src/pages/toddle-enhancement-extension.astro b/src/pages/toddle-enhancement-extension.astro index d9cb5ad..31cf342 100644 --- a/src/pages/toddle-enhancement-extension.astro +++ b/src/pages/toddle-enhancement-extension.astro @@ -383,8 +383,8 @@ const schema = [ The extension no longer hides Toddle's own flags: they stay where Toddle puts them, with their links and documents in Toddle's student popover. Concealing them is your choice: a new install starts with flags shown, and if you are - updating from 0.8.2, where flags were hidden by default, they stay concealed until - you show them. {flags.reveal} + updating from 0.8.2, where flags were hidden by default, or you had hidden them + yourself, they stay concealed until you show them. {flags.reveal}

From c12ee575d17278ac5f9563edc881f058a6872c5a Mon Sep 17 00:00:00 2001 From: Bryan Fawcett Date: Wed, 7 Oct 2026 11:47:30 +0800 Subject: [PATCH 3/4] docs: re-review fixes: the 0.8.4 fixes reach schools in 0.9.0; every reviewed rebuild step named; llms.txt flags say what 0.8.2 does Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq --- public/llms.txt | 9 +++++---- src/pages/legal/security.astro | 5 +++-- 2 files changed, 8 insertions(+), 6 deletions(-) diff --git a/public/llms.txt b/public/llms.txt index dba12f3..57985b7 100644 --- a/public/llms.txt +++ b/public/llms.txt @@ -57,7 +57,7 @@ community-based platforms. Nyuchi Web Services is its development division. primary teacher names; the Attendance dashboard's year groups and the teacher of each student's current class; and, in the sidebar, the student's details, contacts, classes, today's timetable and attendance, - and their active flags. It notes the sign-in headers and + and their flags. It notes the sign-in headers and academic year from Toddle's own requests only to ask Toddle as the teacher; it never asks for a password. Nothing it reads leaves the browser except back to Toddle; it transmits nothing from Toddle to anyone else: no @@ -68,9 +68,10 @@ community-based platforms. Nyuchi Web Services is its development division. email domain), which is compared with the signed-in Toddle account inside the browser only. An organisation licence is one key for the school's email domain: anyone signed in to Toddle with an address at that domain is - covered. From version 0.9.0 the sidebar asks Toddle for a student's flags - each time it opens, - and keeps them only while it is open. Apart + covered. From version 0.9.0 the sidebar asks Toddle for a student's + active flags each time it opens, and keeps them only while it is open; in + version 0.8.2, while flags are hidden, it asks only when someone presses + its eye button. Apart from Toddle, it has two outside connections, neither carrying Toddle data. (1) Opt-in feedback: the toolbar menu's "Send feedback" form, which, only when the person presses Send, sends what they typed (topic, message, and an email only if they diff --git a/src/pages/legal/security.astro b/src/pages/legal/security.astro index bce247b..6685ce4 100644 --- a/src/pages/legal/security.astro +++ b/src/pages/legal/security.astro @@ -60,7 +60,7 @@ const glance = [ }, { label: "Reviewed", - value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, and to be released to schools in ${security.next}.`, + value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, whose fixes reach schools in 0.9.0.`, }, ]; @@ -511,7 +511,8 @@ const severityClass: Record = { medium-severity issues and two low (findings {secondReview.findings}). All were fixed in version {secondReview.version}, and the fixes are in every release after it, including {security.next}. None was in version {security.version}. Each later - step of the rebuild (the student sidebar, the home page) was reviewed the same way as + step of the rebuild (the student sidebar, the home page, the gradebook's toolbar and + the Attendance dashboard's details) was reviewed the same way as it was made, and what those reviews found about the page's limits is set out below.

From 2ea707f15d1b1d83caa9811177d34a16f3238805 Mon Sep 17 00:00:00 2001 From: Bryan Fawcett Date: Wed, 7 Oct 2026 11:48:48 +0800 Subject: [PATCH 4/4] docs: the extension page's flags paragraph says from which version Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq --- src/pages/toddle-enhancement-extension.astro | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/pages/toddle-enhancement-extension.astro b/src/pages/toddle-enhancement-extension.astro index bc2dc24..774314b 100644 --- a/src/pages/toddle-enhancement-extension.astro +++ b/src/pages/toddle-enhancement-extension.astro @@ -380,8 +380,8 @@ const schema = [ room should not be reading over your shoulder.

- The extension no longer hides Toddle's own flags: they stay where Toddle puts - them, with their links and documents in Toddle's student popover. Concealing + From version {extensionVersions.next}, the extension no longer hides Toddle's own + flags: they stay where Toddle puts them, with their links and documents in Toddle's student popover. Concealing them is your choice: a new install starts with flags shown, and if you are updating from 0.8.2, where flags were hidden by default, or you had hidden them yourself, they stay concealed until you show them. {flags.reveal}