From fbca136351a1b113d682ed81d30e314ad6bba9b5 Mon Sep 17 00:00:00 2001
From: Bryan Fawcett
Date: Tue, 6 Oct 2026 15:58:34 +0800
Subject: [PATCH 1/4] docs: one account of 0.9.0 across the site (review of the
release)
- The extension page and the Security page say the gradebook's toolbar
and the Attendance dashboard's details run in closed shadow roots from
0.9.0, as the releases page and the extension's code (rebuild steps 5
and 7) do; they no longer say these are still moving.
- The second review's fixes are in 0.8.4, a test build, and reach schools
in 0.9.0, not '0.8.4 before it is published'.
- Concealing flags: a new install starts with flags shown; updating from
0.8.2 keeps them concealed. Not 'off until you switch it on'.
- llms.txt: the sidebar asks for a student's active flags each time it
opens, as legal.ts says.
Co-Authored-By: Claude Opus 5.5
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
Signed-off-by: Bryan Fawcett
---
SECURITY.md | 4 ++--
public/llms.txt | 2 +-
src/pages/legal/security.astro | 10 +++++-----
src/pages/toddle-enhancement-extension.astro | 6 ++++--
4 files changed, 12 insertions(+), 10 deletions(-)
diff --git a/SECURITY.md b/SECURITY.md
index 73d3566..76f5ecf 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -4,8 +4,8 @@ This repository is `learning.nyuchi.com`: a static Astro site, served by
Vercel, and the home of the Toddle Enhancement Extension.
The extension's own security model, how it is tested, and its adversarial
-reviews of 1 October 2026 (0.8.2) and 6 October 2026 (0.8.4, before it is
-published), with their findings and the limits of code that runs in Toddle's
+reviews of 1 October 2026 (0.8.2) and 6 October 2026 (0.8.4, a test build;
+its fixes reach schools in 0.9.0), with their findings and the limits of code that runs in Toddle's
page, are published for schools at
[learning.nyuchi.com/legal/security](https://learning.nyuchi.com/legal/security).
The vulnerability disclosure policy, covering this site, the extension and the
diff --git a/public/llms.txt b/public/llms.txt
index bf4515b..bdbbf96 100644
--- a/public/llms.txt
+++ b/public/llms.txt
@@ -56,7 +56,7 @@ community-based platforms. Nyuchi Web Services is its development division.
primary teacher names; the Attendance dashboard's year groups and the
teacher of each student's current class; and, in the sidebar, the
student's details, contacts, classes, today's timetable and attendance,
- and their flags when they are shown. It notes the sign-in headers and
+ and their active flags, asked for each time the sidebar opens. It notes the sign-in headers and
academic year from Toddle's own requests only to ask Toddle as the
teacher; it never asks for a password. Nothing it reads leaves the browser
except back to Toddle; it transmits nothing from Toddle to anyone else: no
diff --git a/src/pages/legal/security.astro b/src/pages/legal/security.astro
index 2150214..f8447f7 100644
--- a/src/pages/legal/security.astro
+++ b/src/pages/legal/security.astro
@@ -60,7 +60,7 @@ const glance = [
},
{
label: "Reviewed",
- value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version} before it is published.`,
+ value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, and released to schools in ${security.next}.`,
},
];
@@ -364,15 +364,15 @@ const severityClass: Record = {
The extension is being rebuilt so that as little of it as possible runs where
Toddle's own scripts run. From version {security.next}, the flag switch, the student
- sidebar with a class's teachers, and the home page's My classes option and teacher
- names run in the extension's own isolated part of the browser. What they draw on
+ sidebar with a class's teachers, the home page's My classes option and teacher
+ names, the gradebook's toolbar and controls, and the Attendance dashboard's details
+ run in the extension's own isolated part of the browser. What they draw on
Toddle's pages sits inside closed shadow roots, which no script on Toddle's page can
read or click into, and whether each one runs is decided by the extension's own
switches and licence, never by Toddle's page. What only Toddle's page holds (who was
clicked, the course list as it loads, Toddle's chat and icons) is read by small parts
with no interface of their own, which talk to the extension on private channels set
- up before Toddle's own scripts run. The gradebook and the Attendance dashboard are
- moving the same way.
+ up before Toddle's own scripts run.
Protections inside the page
diff --git a/src/pages/toddle-enhancement-extension.astro b/src/pages/toddle-enhancement-extension.astro
index dc04194..d9cb5ad 100644
--- a/src/pages/toddle-enhancement-extension.astro
+++ b/src/pages/toddle-enhancement-extension.astro
@@ -177,7 +177,7 @@ const facts = [
{
label: "Where it runs",
value:
- "Only on web.toddleapp.com. It has no access to any other site. From version 0.9.0 the flag switch, the student sidebar and the home page's additions run in the extension's own isolated part of the browser, drawn inside closed shadow roots that no script on Toddle's page can read or click into; the gradebook and the Attendance dashboard are moving the same way.",
+ "Only on web.toddleapp.com. It has no access to any other site. From version 0.9.0 the flag switch, the student sidebar, the home page's additions, the gradebook's toolbar and controls, and the Attendance dashboard's details run in the extension's own isolated part of the browser, drawn inside closed shadow roots that no script on Toddle's page can read or click into.",
},
{
label: "What it reads",
@@ -382,7 +382,9 @@ const schema = [
The extension no longer hides Toddle's own flags: they stay where Toddle puts
them, with their links and documents in Toddle's student popover. Concealing
- them is your choice, off until you switch it on. {flags.reveal}
+ them is your choice: a new install starts with flags shown, and if you are
+ updating from 0.8.2, where flags were hidden by default, they stay concealed until
+ you show them. {flags.reveal}
From f7628de7d9af97fc5a85552a922bf6eca2d631d5 Mon Sep 17 00:00:00 2001
From: Bryan Fawcett
Date: Tue, 6 Oct 2026 15:59:55 +0800
Subject: [PATCH 2/4] docs: re-review fixes: 0.9.0 is still to come; llms.txt
matches the pages
Co-Authored-By: Claude Opus 5.5
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
Signed-off-by: Bryan Fawcett
---
public/llms.txt | 10 ++++++----
src/pages/legal/security.astro | 2 +-
src/pages/toddle-enhancement-extension.astro | 4 ++--
3 files changed, 9 insertions(+), 7 deletions(-)
diff --git a/public/llms.txt b/public/llms.txt
index bdbbf96..3a776a9 100644
--- a/public/llms.txt
+++ b/public/llms.txt
@@ -44,8 +44,9 @@ community-based platforms. Nyuchi Web Services is its development division.
course, room and every teacher with their display title and email; the
teachers can be emailed together. Message buttons open Toddle's own chat;
the extension sends no message itself. From version 0.9.0 the flag switch,
- the student sidebar and the home page's additions run in the extension's
- own isolated world, drawn in closed shadow roots that no script on
+ the student sidebar, the home page's additions, the gradebook's toolbar
+ and controls, and the Attendance dashboard's details run in the
+ extension's own isolated world, drawn in closed shadow roots that no script on
Toddle's page can read or click into. On the Attendance dashboard's Students
tab, each student's year group and current class and teacher appear under
their name, and the current block's column is outlined. It reads Toddle in
@@ -56,7 +57,7 @@ community-based platforms. Nyuchi Web Services is its development division.
primary teacher names; the Attendance dashboard's year groups and the
teacher of each student's current class; and, in the sidebar, the
student's details, contacts, classes, today's timetable and attendance,
- and their active flags, asked for each time the sidebar opens. It notes the sign-in headers and
+ and their active flags. It notes the sign-in headers and
academic year from Toddle's own requests only to ask Toddle as the
teacher; it never asks for a password. Nothing it reads leaves the browser
except back to Toddle; it transmits nothing from Toddle to anyone else: no
@@ -67,7 +68,8 @@ community-based platforms. Nyuchi Web Services is its development division.
email domain), which is compared with the signed-in Toddle account inside
the browser only. An organisation licence is one key for the school's
email domain: anyone signed in to Toddle with an address at that domain is
- covered. The sidebar asks Toddle for a student's flags each time it opens,
+ covered. From version 0.9.0 the sidebar asks Toddle for a student's flags
+ each time it opens,
and keeps them only while it is open. Apart
from Toddle, it has two outside connections, neither carrying Toddle
data. (1) Opt-in feedback: the toolbar menu's "Send feedback" form, which, only when the person presses
diff --git a/src/pages/legal/security.astro b/src/pages/legal/security.astro
index f8447f7..2c546a3 100644
--- a/src/pages/legal/security.astro
+++ b/src/pages/legal/security.astro
@@ -60,7 +60,7 @@ const glance = [
},
{
label: "Reviewed",
- value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, and released to schools in ${security.next}.`,
+ value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, and to be released to schools in ${security.next}.`,
},
];
diff --git a/src/pages/toddle-enhancement-extension.astro b/src/pages/toddle-enhancement-extension.astro
index d9cb5ad..31cf342 100644
--- a/src/pages/toddle-enhancement-extension.astro
+++ b/src/pages/toddle-enhancement-extension.astro
@@ -383,8 +383,8 @@ const schema = [
The extension no longer hides Toddle's own flags: they stay where Toddle puts
them, with their links and documents in Toddle's student popover. Concealing
them is your choice: a new install starts with flags shown, and if you are
- updating from 0.8.2, where flags were hidden by default, they stay concealed until
- you show them. {flags.reveal}
+ updating from 0.8.2, where flags were hidden by default, or you had hidden them
+ yourself, they stay concealed until you show them. {flags.reveal}
From c12ee575d17278ac5f9563edc881f058a6872c5a Mon Sep 17 00:00:00 2001
From: Bryan Fawcett
Date: Wed, 7 Oct 2026 11:47:30 +0800
Subject: [PATCH 3/4] docs: re-review fixes: the 0.8.4 fixes reach schools in
0.9.0; every reviewed rebuild step named; llms.txt flags say what 0.8.2 does
Co-Authored-By: Claude Opus 5.5
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
---
public/llms.txt | 9 +++++----
src/pages/legal/security.astro | 5 +++--
2 files changed, 8 insertions(+), 6 deletions(-)
diff --git a/public/llms.txt b/public/llms.txt
index dba12f3..57985b7 100644
--- a/public/llms.txt
+++ b/public/llms.txt
@@ -57,7 +57,7 @@ community-based platforms. Nyuchi Web Services is its development division.
primary teacher names; the Attendance dashboard's year groups and the
teacher of each student's current class; and, in the sidebar, the
student's details, contacts, classes, today's timetable and attendance,
- and their active flags. It notes the sign-in headers and
+ and their flags. It notes the sign-in headers and
academic year from Toddle's own requests only to ask Toddle as the
teacher; it never asks for a password. Nothing it reads leaves the browser
except back to Toddle; it transmits nothing from Toddle to anyone else: no
@@ -68,9 +68,10 @@ community-based platforms. Nyuchi Web Services is its development division.
email domain), which is compared with the signed-in Toddle account inside
the browser only. An organisation licence is one key for the school's
email domain: anyone signed in to Toddle with an address at that domain is
- covered. From version 0.9.0 the sidebar asks Toddle for a student's flags
- each time it opens,
- and keeps them only while it is open. Apart
+ covered. From version 0.9.0 the sidebar asks Toddle for a student's
+ active flags each time it opens, and keeps them only while it is open; in
+ version 0.8.2, while flags are hidden, it asks only when someone presses
+ its eye button. Apart
from Toddle, it has two outside connections, neither carrying Toddle
data. (1) Opt-in feedback: the toolbar menu's "Send feedback" form, which, only when the person presses
Send, sends what they typed (topic, message, and an email only if they
diff --git a/src/pages/legal/security.astro b/src/pages/legal/security.astro
index bce247b..6685ce4 100644
--- a/src/pages/legal/security.astro
+++ b/src/pages/legal/security.astro
@@ -60,7 +60,7 @@ const glance = [
},
{
label: "Reviewed",
- value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, and to be released to schools in ${security.next}.`,
+ value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, whose fixes reach schools in 0.9.0.`,
},
];
@@ -511,7 +511,8 @@ const severityClass: Record = {
medium-severity issues and two low (findings {secondReview.findings}). All were fixed
in version {secondReview.version}, and the fixes are in every release after it,
including {security.next}. None was in version {security.version}. Each later
- step of the rebuild (the student sidebar, the home page) was reviewed the same way as
+ step of the rebuild (the student sidebar, the home page, the gradebook's toolbar and
+ the Attendance dashboard's details) was reviewed the same way as
it was made, and what those reviews found about the page's limits is set out below.
From 2ea707f15d1b1d83caa9811177d34a16f3238805 Mon Sep 17 00:00:00 2001
From: Bryan Fawcett
Date: Wed, 7 Oct 2026 11:48:48 +0800
Subject: [PATCH 4/4] docs: the extension page's flags paragraph says from
which version
Co-Authored-By: Claude Opus 5.5
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
---
src/pages/toddle-enhancement-extension.astro | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/src/pages/toddle-enhancement-extension.astro b/src/pages/toddle-enhancement-extension.astro
index bc2dc24..774314b 100644
--- a/src/pages/toddle-enhancement-extension.astro
+++ b/src/pages/toddle-enhancement-extension.astro
@@ -380,8 +380,8 @@ const schema = [
room should not be reading over your shoulder.
- The extension no longer hides Toddle's own flags: they stay where Toddle puts
- them, with their links and documents in Toddle's student popover. Concealing
+ From version {extensionVersions.next}, the extension no longer hides Toddle's own
+ flags: they stay where Toddle puts them, with their links and documents in Toddle's student popover. Concealing
them is your choice: a new install starts with flags shown, and if you are
updating from 0.8.2, where flags were hidden by default, or you had hidden them
yourself, they stay concealed until you show them. {flags.reveal}