Skip to content

Releases: ScriptKittyOS/kotiko

Kotiko 1.0.1

Choose a tag to compare

@github-actions github-actions released this 08 Oct 02:36
9514eb1

The first version in the stores. It fixes the package so the Chrome Web Store accepts it;
nothing else changes from 1.0.0, whose notes below describe the release.

  • The Chrome Web Store accepts the package: the Spanish translation now has the extension's
    full name, which the store requires for every language a package includes.

Bug fixes

  • extension: the Spanish translation has the store name Chrome requires (6730d6b)

Install or update

  • Extension: Chrome Web Store (link added after the first review) or Firefox Add-ons (link added after the first review). Stores update installed copies on their own.
  • Server (optional): in your Kotiko folder run git pull, then restart it (./run.sh, or systemctl --user restart kotiko). See Updating.
  • Extension 1.0 works with server 1.0.

Verify the files

The zips are the store packages, built from this tag; anyone can rebuild them byte for byte
(how). They contain only files from extension/ and the
license texts, no third-party code. The server's dependencies are listed in the attached CycloneDX
SBOM. Full steps, including checking the tag's signature: docs/verify.md.

sha256sum -c SHA256SUMS
gh attestation verify kotiko-chrome-1.0.1.zip --repo ScriptKittyOS/kotiko
gh attestation verify kotiko-firefox-1.0.1.zip --repo ScriptKittyOS/kotiko

Kotiko 1.0.0

Choose a tag to compare

@github-actions github-actions released this 08 Oct 01:29
ddf0e9c

Kotiko's first public release, for the Chrome Web Store and Firefox Add-ons. Learn a word in
any language and Kotiko slips it into the pages you already read, in whatever language you
read them; point at it to see what it means and how it's said. Your words stay in your
browser, lookups use your own AI key (a free OpenRouter key works) or a model on your own
computer, and an optional server of your own keeps your words in one place.

Upgrade notes

For anyone updating from Slovo 0.2, or running their own server:

  • Slovo is now Kotiko. The data folder, service name, environment variables
    (KOTIKO_DATA_DIR, KOTIKO_LOG_SQL) and pairing prefix are renamed. The server moves
    your words and access key across on its first start; see the README's "Updating from
    Slovo".
  • Update the server and the extension together. The extension no longer sends your
    server's access key: it signs each request (Kotiko-HMAC v2) and checks the server's
    signed answers. An older server turns signed requests away, and Kotiko asks you to update
    it. Tools such as curl can still send the key as a Bearer token.
  • The server's address is http://127.0.0.1:4747. A saved http://localhost:… address
    moves to 127.0.0.1 on its own. The server now listens on both 127.0.0.1 and ::1, and
    won't start if another program already holds either.
  • The words table is rebuilt on the server's first start. Going back to 0.2 needs the
    automatic backup the server makes first.
  • The server refuses to start on an unsafe data folder: one owned by another account,
    holding links where Kotiko's files go, or writable by others while holding other files. It
    says what it found and how to fix it.
  • LLM_URL, TRANSCRIBE_URL and PUBLIC_URL can't hold a user name or password; put
    keys in LLM_API_KEY or TRANSCRIBE_API_KEY (or their _FILE forms).
  • Behind a reverse proxy, set TRUSTED_PROXY_HEADER so each client gets its own limit
    on wrong keys; otherwise all proxied clients share one.
  • /health answers JSON (still 200 when healthy, 503 when the database fails), every
    other path needs the access key however it's spelled, and run.sh runs in production
    unless MIX_ENV is set.

Security

Before this release, six independent reviewers attacked four release candidates. Every
finding at medium or above, and almost every lower one, was fixed with a regression test;
what remains is listed as accepted risks in the report,
docs/security/review-v1.0.0.md. No published version was
affected, so there are no advisories.

  • Security: a web page could restyle a swapped word (it sits in the page) so that it
    covered the page invisibly; then your pointer resting anywhere, or your click on one of
    the page's own buttons, opened the word's card, and the page could search the card's
    text for guesses. The card now opens only on a swapped word you can see, and from the
    mouse or a tap only when you point at the word itself. Enter on a focused word still
    opens it. The privacy policy (version 5) says so.

  • Security: Kotiko swapped words in text a page had hidden with a see-through filter, a
    clipping shape or a mask, so the page could read those swaps and learn your words. Text
    like that, and text faded to under 10 % opacity, is no longer swapped. Kotiko also
    leaves text under any clipping shape or mask alone, even where you can see it, since it
    can't tell how much of it shows.

  • Security: Kotiko no longer sends your server's access key; it signs each request. Your
    server signs each answer too, and Kotiko uses an answer only when it carries that
    signature, so if another program takes your server's place (say, while the server
    restarts) it gets neither your key nor your words. Update the server and extension
    together: an older server turns signed requests away, and Kotiko asks you to update it.
    Tools such as curl can still send the key as before. The privacy policy (version 4)
    says so.

  • Security: a web page, or any program on your computer, could lock Kotiko out of your
    server for a minute by sending it a burst of wrong keys or malformed checks. Requests
    from your own computer are no longer locked out; requests from other computers still
    are, including those a reverse proxy on your computer passes on.

  • Security: the server warns when it would send an API key over plain HTTP to another
    machine, but missed an address written in capitals, such as HTTP://203.0.113.7/v1. It
    now warns however the address is written. An OpenRouter address in capitals is also
    recognised as OpenRouter.

  • Security: a program that took your server's place while it was stopped could keep a
    request Kotiko sent it and play it to your server once it was back, and get your word
    list, when the clock of the computer Kotiko runs on was ahead of the server's. Your
    server now makes a new random id each time it starts, gives it with its proof, and
    accepts only requests signed with the current one; after a restart Kotiko asks for a
    new proof and sends the request again by itself. Update the server and the extension
    together: each turns the other's older version away and says so.

  • Security: a Kotiko server set to a model of its own (LLM_MODEL), for example on a paid
    provider, sent no limit on how long an answer may be, so a model that kept writing could
    cost you up to the provider's own limit for one word. Every lookup now asks for at most
    1,200 tokens of answer (4,000 for refreshing pronunciations), like the extension does,
    in the field OpenAI expects when LLM_URL is OpenAI's.

  • Security: a web page could read your word list. It could hide a long list of words on
    the page, where you'd never see them, and read back which ones Kotiko swapped. Kotiko
    now swaps only words you can see: text a page hides isn't touched, and text below the
    screen is swapped as you scroll to it, which also makes very long pages faster. One
    visit to a page swaps at most 500 different words, each in at most 3 of your languages,
    so no page can read your whole list at once. The privacy policy (version 3) says what
    sites can and can't see.

  • Security: any web page could switch Kotiko off on itself, and could tell that you use
    Kotiko even on sites you paused, on sites Kotiko leaves alone such as banks, or with
    Kotiko turned off. Where Kotiko doesn't swap, it now adds nothing to the page.

  • Security: a web page could open a word's card with a fake click and search the card's
    text. The card now opens only when you point at, click, tap or press a key on a word.

  • Security: the popup's "This page is in …" line showed the page's own language label as
    written, so a page could put any sentence it liked in Kotiko's popup. Kotiko now shows
    only a language name your browser knows, and nothing otherwise.

  • Security: before Kotiko sends your server's access key, the server must now show it holds
    the same key, without either side sending it. Another program listening at the address
    (for example while your server is stopped) never gets the key. Update your Kotiko server
    along with the extension: an older server can't show it, and Kotiko says so in Settings.

  • Security: after "Delete everything", Kotiko starts afresh and no longer takes an old-style
    server address and token that a page's script left in the browser's storage meanwhile.

  • Security: Kotiko's default server address is now http://127.0.0.1:4747, and an address
    you type as http://localhost:… is used as 127.0.0.1, for your server and for Ollama
    and LM Studio. Browsers try localhost at the IPv6 address [::1] first, where another
    account on the same computer could listen and receive your server's access token. An
    address saved as localhost moves to 127.0.0.1 on update; nothing to do on your side.

  • Security: a web page that managed to run code inside Kotiko's page script could change
    Kotiko's settings, because browsers let that script write Kotiko's storage. It could turn
    Kotiko off, pause sites, hide languages, change the words pages show, queue a word to be
    looked up with your own AI key and saved, pick another model, or change the languages
    your server's Telegram bot answers in. Kotiko now keeps the real copy of all of these
    where page scripts can't reach, puts back anything changed elsewhere, and only its own
    pages change settings. Nothing to do on your side; your settings move over on update.
    In Firefox (and Chrome before 140), the languages you read no longer follow from
    Kotiko in your other browsers: set them in each one.

Your own server

  • Self-hosted server: the two addresses that answer without your access key, /health and
    /api/v1/proof, also answered when written another way, such as /health/ or
    //api/v1/proof. Now only the exact addresses do; any other spelling needs the key.

  • Self-hosted server: a key written in the query of LLM_URL or TRANSCRIBE_URL (some
    providers take ?key=...) was written to the log at start. The log now shows the address
    without its query (https://host/v1?…), and the query's values are taken out of every
    log line. A query such as ?api-version=... now also reaches the provider on every
    request, after the path.

  • Self-hosted server behind a reverse proxy: everyone the proxy passes on was counted as
    one, so a stranger sending ten wrong keys a minute could keep your other devices out
    for as long as they kept at it. Set the new TRUSTED_PROXY_HEADER to the header your
    proxy puts each visitor's address in (x-forwarded-for, x-real-ip,
    cf-connecting-ip or forwarded), and each visitor is counted on their own. The server
    also recognises more of the headers proxies add (Via, X-Client-IP,
    Fastly-Client-IP and others), so visitors through such a proxy are no longer taken for
    your own computer, which is never limited.

  • Self-hosted server: after moving your ...

Read more

Kotiko 1.0.0-rc.4

Kotiko 1.0.0-rc.4 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 07 Oct 22:30
01312d2

Release candidate 4 of Kotiko 1.0.0, for review and testing. It isn't sent to the stores.

To try it, unzip a zip and load the folder unpacked (Chrome: chrome://extensions, Developer mode,
Load unpacked; Firefox: about:debugging, This Firefox, Load Temporary Add-on).


Install or update

  • Extension: Chrome Web Store (link added after the first review) or Firefox Add-ons (link added after the first review). Stores update installed copies on their own.
  • Server (optional): in your Kotiko folder run git pull, then restart it (./run.sh, or systemctl --user restart kotiko). See Updating.
  • Extension 1.0 works with server 1.0.

Verify the files

The zips are the store packages, built from this tag; anyone can rebuild them byte for byte
(how). They contain only files from extension/ and the
license texts, no third-party code. The server's dependencies are listed in the attached CycloneDX
SBOM. Full steps, including checking the tag's signature: docs/verify.md.

sha256sum -c SHA256SUMS
gh attestation verify kotiko-chrome-1.0.0-rc.4.zip --repo ScriptKittyOS/kotiko
gh attestation verify kotiko-firefox-1.0.0-rc.4.zip --repo ScriptKittyOS/kotiko

Kotiko 1.0.0-rc.3

Kotiko 1.0.0-rc.3 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 07 Oct 18:33
088bbea

Release candidate 3 of Kotiko 1.0.0, for review and testing. It isn't sent to the stores.

To try it, unzip a zip and load the folder unpacked (Chrome: chrome://extensions, Developer mode,
Load unpacked; Firefox: about:debugging, This Firefox, Load Temporary Add-on).


Install or update

  • Extension: Chrome Web Store (link added after the first review) or Firefox Add-ons (link added after the first review). Stores update installed copies on their own.
  • Server (optional): in your Kotiko folder run git pull, then restart it (./run.sh, or systemctl --user restart kotiko). See Updating.
  • Extension 1.0 works with server 1.0.

Verify the files

The zips are the store packages, built from this tag; anyone can rebuild them byte for byte
(how). They contain only files from extension/ and the
license texts, no third-party code. The server's dependencies are listed in the attached CycloneDX
SBOM. Full steps, including checking the tag's signature: docs/verify.md.

sha256sum -c SHA256SUMS
gh attestation verify kotiko-chrome-1.0.0-rc.3.zip --repo ScriptKittyOS/kotiko
gh attestation verify kotiko-firefox-1.0.0-rc.3.zip --repo ScriptKittyOS/kotiko

Kotiko 1.0.0-rc.2

Kotiko 1.0.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 07 Oct 15:26
9b5a6df

Release candidate 2 of Kotiko 1.0.0, for review and testing. It isn't sent to the stores.

To try it, unzip a zip and load the folder unpacked (Chrome: chrome://extensions, Developer mode,
Load unpacked; Firefox: about:debugging, This Firefox, Load Temporary Add-on).


Install or update

  • Extension: Chrome Web Store (link added after the first review) or Firefox Add-ons (link added after the first review). Stores update installed copies on their own.
  • Server (optional): in your Kotiko folder run git pull, then restart it (./run.sh, or systemctl --user restart kotiko). See Updating.
  • Extension 1.0 works with server 1.0.

Verify the files

The zips are the store packages, built from this tag; anyone can rebuild them byte for byte
(how). They contain only files from extension/ and the
license texts, no third-party code. The server's dependencies are listed in the attached CycloneDX
SBOM. Full steps, including checking the tag's signature: docs/verify.md.

sha256sum -c SHA256SUMS
gh attestation verify kotiko-chrome-1.0.0-rc.2.zip --repo ScriptKittyOS/kotiko
gh attestation verify kotiko-firefox-1.0.0-rc.2.zip --repo ScriptKittyOS/kotiko