docs: align published and security guidance
This commit is contained in:
@@ -15,6 +15,8 @@ This document is a drafting and validation aid. Compare all privacy answers with
|
||||
- Support URL: https://napper.au/lildra/support
|
||||
- Privacy-policy URL: https://napper.au/lildra/privacy
|
||||
- Homepage: https://napper.au/lildra
|
||||
- Public source: https://git.napper.au/napper/lildra
|
||||
- Publication status: publicly listed in the Chrome Web Store and Microsoft Edge Add-ons
|
||||
|
||||
### Short description
|
||||
|
||||
@@ -116,7 +118,7 @@ Browser chrome was cropped to remove the production hostname, course identifiers
|
||||
|
||||
## Store icon validation
|
||||
|
||||
The 0.3.0 packaged icon was fully opaque and had an unintended white square background. For 0.3.1, the established mark was technically normalised without redesigning it:
|
||||
The previous packaged icon was fully opaque and had an unintended white square background. For 0.3.1, the established mark was technically normalised without redesigning it:
|
||||
|
||||
- 128×128 PNG: confirmed.
|
||||
- Alpha transparency and transparent corners: confirmed.
|
||||
@@ -136,18 +138,26 @@ The 0.3.0 packaged icon was fully opaque and had an unintended white square back
|
||||
|
||||
## Public website alignment
|
||||
|
||||
Confirmed strengths:
|
||||
Current published alignment:
|
||||
|
||||
- `/lildra`, `/lildra/privacy`, `/lildra/support`, and `/lildra/terms` are live.
|
||||
- The public pages accurately describe explicit activation, supported page types, lack of persistent host access, local processing, permissions, and independence.
|
||||
- The public privacy page discloses local access to the active URL, title, and Canvas structure.
|
||||
|
||||
Required before submission:
|
||||
- The website displays version 0.3.1 and uses **Local processing only** to explain that the selected lesson is processed in the browser and is not stored or transmitted by Lildra.
|
||||
- Normal installation links point to the Chrome Web Store and Microsoft Edge Add-ons.
|
||||
- Version 0.3.1 is publicly listed in both stores.
|
||||
|
||||
1. Update visible version references from `0.3.0` to `0.3.1`.
|
||||
2. On the homepage privacy card, replace **“No data collection”** with **“Local processing only”** and use: “The selected lesson is processed in your browser and is not stored or transmitted by Lildra.” This avoids ambiguity under Chrome's definition of data handling.
|
||||
3. After Web Store publication, replace release-download installation calls to action with the Chrome Web Store listing. The support page may retain a source/release link as a secondary option.
|
||||
4. Update support installation instructions after publication so normal users install from the store rather than enabling Developer mode.
|
||||
Local processing is not the same as handling no website content. Lildra temporarily processes the selected supported page's address, Canvas DOM structure, and visible title on the device. It does not collect that information into an extension dataset, persistently store it, or transmit it. Keep the conservative **Website content: Yes** dashboard disclosure.
|
||||
|
||||
## Microsoft Edge listing alignment
|
||||
|
||||
- [ ] Chrome and Edge detailed descriptions describe the same single purpose and supported routes.
|
||||
- [ ] Both listings show version 0.3.1.
|
||||
- [ ] Both listings use https://napper.au/lildra/support as the support URL.
|
||||
- [ ] Both listings use https://napper.au/lildra/privacy as the privacy-policy URL.
|
||||
- [ ] Both listings describe local processing without claiming that Lildra handles no website content.
|
||||
- [ ] Both listings identify the public source at https://git.napper.au/napper/lildra where the dashboard supports it.
|
||||
|
||||
## Manual submission and testing checklist
|
||||
|
||||
@@ -171,9 +181,9 @@ Required before submission:
|
||||
- [ ] Upload the privacy-policy URL and compare every dashboard privacy answer against its current wording.
|
||||
- [ ] Provide any reviewer credentials only through the dashboard's secure field.
|
||||
|
||||
## Distribution recommendation
|
||||
## Published-listing maintenance
|
||||
|
||||
Use **Unlisted** for the first controlled beta. The implementation and submission package are narrowly scoped, but representative live QLearn testing, the 0.3.1 public-site wording updates, icon checks in Chrome, and dashboard privacy-category review remain manual. Move to **Public** after those checks pass and the store/support links are aligned.
|
||||
Version 0.3.1 is publicly listed in the Chrome Web Store and Microsoft Edge Add-ons. Before a future release, repeat the manual testing and dashboard review above, then ensure both stores, the website, privacy policy, support page, terms, and public source remain aligned. Dashboard values and live listing text must be checked manually because they are not controlled by this repository.
|
||||
|
||||
## Official references
|
||||
|
||||
|
||||
Reference in New Issue
Block a user