Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,8 @@ This repository is `learning.nyuchi.com`: a static Astro site, served by
Vercel, and the home of the Toddle Enhancement Extension.

The extension's own security model, how it is tested, and its adversarial
reviews of 1 October 2026 (0.8.2) and 6 October 2026 (0.8.4, before it is
published), with their findings and the limits of code that runs in Toddle's
reviews of 1 October 2026 (0.8.2) and 6 October 2026 (0.8.4, a test build;
its fixes reach schools in 0.9.0), with their findings and the limits of code that runs in Toddle's
page, are published for schools at
[learning.nyuchi.com/legal/security](https://learning.nyuchi.com/legal/security).
The vulnerability disclosure policy, covering this site, the extension and the
Expand Down
13 changes: 8 additions & 5 deletions public/llms.txt
Original file line number Diff line number Diff line change
Expand Up @@ -44,8 +44,9 @@ community-based platforms. Nyuchi Web Services is its development division.
course, room and every teacher with their display title and email; the
teachers can be emailed together. Message buttons open Toddle's own chat;
the extension sends no message itself. From version 0.9.0 the flag switch,
the student sidebar and the home page's additions run in the extension's
own isolated world, drawn in closed shadow roots that no script on
the student sidebar, the home page's additions, the gradebook's toolbar
and controls, and the Attendance dashboard's details run in the
extension's own isolated world, drawn in closed shadow roots that no script on
Toddle's page can read or click into. On the Attendance dashboard's Students
tab, each student's year group and current class and teacher appear under
their name, and the current block's column is outlined. It reads Toddle in
Expand All @@ -56,7 +57,7 @@ community-based platforms. Nyuchi Web Services is its development division.
primary teacher names; the Attendance dashboard's year groups and the
teacher of each student's current class; and, in the sidebar, the
student's details, contacts, classes, today's timetable and attendance,
and their flags when they are shown. It notes the sign-in headers and
and their flags. It notes the sign-in headers and
academic year from Toddle's own requests only to ask Toddle as the
teacher; it never asks for a password. Nothing it reads leaves the browser
except back to Toddle; it transmits nothing from Toddle to anyone else: no
Expand All @@ -67,8 +68,10 @@ community-based platforms. Nyuchi Web Services is its development division.
email domain), which is compared with the signed-in Toddle account inside
the browser only. An organisation licence is one key for the school's
email domain: anyone signed in to Toddle with an address at that domain is
covered. The sidebar asks Toddle for a student's flags each time it opens,
and keeps them only while it is open. Apart
covered. From version 0.9.0 the sidebar asks Toddle for a student's
active flags each time it opens, and keeps them only while it is open; in
version 0.8.2, while flags are hidden, it asks only when someone presses
its eye button. Apart
from Toddle, it has two outside connections, neither carrying Toddle
data. (1) Opt-in feedback: the toolbar menu's "Send feedback" form, which, only when the person presses
Send, sends what they typed (topic, message, and an email only if they
Expand Down
13 changes: 7 additions & 6 deletions src/pages/legal/security.astro
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ const glance = [
},
{
label: "Reviewed",
value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version} before it is published.`,
value: `Two adversarial reviews: ${firstReview.label}, every finding fixed in ${firstReview.version}; and ${secondReview.label}, every finding fixed in ${secondReview.version}, a test build, whose fixes reach schools in 0.9.0.`,
},
];

Expand Down Expand Up @@ -365,15 +365,15 @@ const severityClass: Record<string, string> = {
<p class="mt-2 text-body text-muted-foreground text-pretty">
The extension is being rebuilt so that as little of it as possible runs where
Toddle's own scripts run. From version {security.next}, the flag switch, the student
sidebar with a class's teachers, and the home page's My classes option and teacher
names run in the extension's own isolated part of the browser. What they draw on
sidebar with a class's teachers, the home page's My classes option and teacher
names, the gradebook's toolbar and controls, and the Attendance dashboard's details
run in the extension's own isolated part of the browser. What they draw on
Toddle's pages sits inside closed shadow roots, which no script on Toddle's page can
read or click into, and whether each one runs is decided by the extension's own
switches and licence, never by Toddle's page. What only Toddle's page holds (who was
clicked, the course list as it loads, Toddle's chat and icons) is read by small parts
with no interface of their own, which talk to the extension on private channels set
up before Toddle's own scripts run. The gradebook and the Attendance dashboard are
moving the same way.
up before Toddle's own scripts run.
</p>

<h3 class="font-serif text-h5 text-foreground mt-8">Protections inside the page</h3>
Expand Down Expand Up @@ -511,7 +511,8 @@ const severityClass: Record<string, string> = {
medium-severity issues and two low (findings {secondReview.findings}). All were fixed
in version {secondReview.version}, and the fixes are in every release after it,
including {security.next}. None was in version {security.version}. Each later
step of the rebuild (the student sidebar, the home page) was reviewed the same way as
step of the rebuild (the student sidebar, the home page, the gradebook's toolbar and
the Attendance dashboard's details) was reviewed the same way as
it was made, and what those reviews found about the page's limits is set out below.
</p>
<div class="mt-6 space-y-4">
Expand Down
10 changes: 6 additions & 4 deletions src/pages/toddle-enhancement-extension.astro
Original file line number Diff line number Diff line change
Expand Up @@ -177,7 +177,7 @@ const facts = [
{
label: "Where it runs",
value:
"Only on web.toddleapp.com. It has no access to any other site. From version 0.9.0 the flag switch, the student sidebar and the home page's additions run in the extension's own isolated part of the browser, drawn inside closed shadow roots that no script on Toddle's page can read or click into; the gradebook and the Attendance dashboard are moving the same way.",
"Only on web.toddleapp.com. It has no access to any other site. From version 0.9.0 the flag switch, the student sidebar, the home page's additions, the gradebook's toolbar and controls, and the Attendance dashboard's details run in the extension's own isolated part of the browser, drawn inside closed shadow roots that no script on Toddle's page can read or click into.",
},
{
label: "What it reads",
Expand Down Expand Up @@ -380,9 +380,11 @@ const schema = [
room should not be reading over your shoulder.
</p>
<p class="mt-3 text-body-sm text-muted-foreground text-pretty">
The extension no longer hides Toddle's own flags: they stay where Toddle puts
them, with their links and documents in Toddle's student popover. Concealing
them is your choice, off until you switch it on. {flags.reveal}
From version {extensionVersions.next}, the extension no longer hides Toddle's own
flags: they stay where Toddle puts them, with their links and documents in Toddle's student popover. Concealing
them is your choice: a new install starts with flags shown, and if you are
updating from 0.8.2, where flags were hidden by default, or you had hidden them
yourself, they stay concealed until you show them. {flags.reveal}
</p>
</div>

Expand Down
Loading