Repository navigation
Releases: ScriptKittyOS/kotiko
Release list
Kotiko 1.0.1
The first version in the stores. It fixes the package so the Chrome Web Store accepts it;
nothing else changes from 1.0.0, whose notes below describe the release.
- The Chrome Web Store accepts the package: the Spanish translation now has the extension's
full name, which the store requires for every language a package includes.
Bug fixes
- extension: the Spanish translation has the store name Chrome requires (6730d6b)
Install or update
- Extension: Chrome Web Store (link added after the first review) or Firefox Add-ons (link added after the first review). Stores update installed copies on their own.
- Server (optional): in your Kotiko folder run
git pull, then restart it (./run.sh, orsystemctl --user restart kotiko). See Updating. - Extension 1.0 works with server 1.0.
Verify the files
The zips are the store packages, built from this tag; anyone can rebuild them byte for byte
(how). They contain only files from extension/ and the
license texts, no third-party code. The server's dependencies are listed in the attached CycloneDX
SBOM. Full steps, including checking the tag's signature: docs/verify.md.
sha256sum -c SHA256SUMS
gh attestation verify kotiko-chrome-1.0.1.zip --repo ScriptKittyOS/kotiko
gh attestation verify kotiko-firefox-1.0.1.zip --repo ScriptKittyOS/kotiko
Kotiko 1.0.0
Kotiko's first public release, for the Chrome Web Store and Firefox Add-ons. Learn a word in
any language and Kotiko slips it into the pages you already read, in whatever language you
read them; point at it to see what it means and how it's said. Your words stay in your
browser, lookups use your own AI key (a free OpenRouter key works) or a model on your own
computer, and an optional server of your own keeps your words in one place.
Upgrade notes
For anyone updating from Slovo 0.2, or running their own server:
- Slovo is now Kotiko. The data folder, service name, environment variables
(KOTIKO_DATA_DIR,KOTIKO_LOG_SQL) and pairing prefix are renamed. The server moves
your words and access key across on its first start; see the README's "Updating from
Slovo". - Update the server and the extension together. The extension no longer sends your
server's access key: it signs each request (Kotiko-HMAC v2) and checks the server's
signed answers. An older server turns signed requests away, and Kotiko asks you to update
it. Tools such ascurlcan still send the key as aBearertoken. - The server's address is
http://127.0.0.1:4747. A savedhttp://localhost:…address
moves to127.0.0.1on its own. The server now listens on both127.0.0.1and::1, and
won't start if another program already holds either. - The words table is rebuilt on the server's first start. Going back to 0.2 needs the
automatic backup the server makes first. - The server refuses to start on an unsafe data folder: one owned by another account,
holding links where Kotiko's files go, or writable by others while holding other files. It
says what it found and how to fix it. LLM_URL,TRANSCRIBE_URLandPUBLIC_URLcan't hold a user name or password; put
keys inLLM_API_KEYorTRANSCRIBE_API_KEY(or their_FILEforms).- Behind a reverse proxy, set
TRUSTED_PROXY_HEADERso each client gets its own limit
on wrong keys; otherwise all proxied clients share one. /healthanswers JSON (still 200 when healthy, 503 when the database fails), every
other path needs the access key however it's spelled, andrun.shruns in production
unlessMIX_ENVis set.
Security
Before this release, six independent reviewers attacked four release candidates. Every
finding at medium or above, and almost every lower one, was fixed with a regression test;
what remains is listed as accepted risks in the report,
docs/security/review-v1.0.0.md. No published version was
affected, so there are no advisories.
-
Security: a web page could restyle a swapped word (it sits in the page) so that it
covered the page invisibly; then your pointer resting anywhere, or your click on one of
the page's own buttons, opened the word's card, and the page could search the card's
text for guesses. The card now opens only on a swapped word you can see, and from the
mouse or a tap only when you point at the word itself. Enter on a focused word still
opens it. The privacy policy (version 5) says so. -
Security: Kotiko swapped words in text a page had hidden with a see-through filter, a
clipping shape or a mask, so the page could read those swaps and learn your words. Text
like that, and text faded to under 10 % opacity, is no longer swapped. Kotiko also
leaves text under any clipping shape or mask alone, even where you can see it, since it
can't tell how much of it shows. -
Security: Kotiko no longer sends your server's access key; it signs each request. Your
server signs each answer too, and Kotiko uses an answer only when it carries that
signature, so if another program takes your server's place (say, while the server
restarts) it gets neither your key nor your words. Update the server and extension
together: an older server turns signed requests away, and Kotiko asks you to update it.
Tools such ascurlcan still send the key as before. The privacy policy (version 4)
says so. -
Security: a web page, or any program on your computer, could lock Kotiko out of your
server for a minute by sending it a burst of wrong keys or malformed checks. Requests
from your own computer are no longer locked out; requests from other computers still
are, including those a reverse proxy on your computer passes on. -
Security: the server warns when it would send an API key over plain HTTP to another
machine, but missed an address written in capitals, such asHTTP://203.0.113.7/v1. It
now warns however the address is written. An OpenRouter address in capitals is also
recognised as OpenRouter. -
Security: a program that took your server's place while it was stopped could keep a
request Kotiko sent it and play it to your server once it was back, and get your word
list, when the clock of the computer Kotiko runs on was ahead of the server's. Your
server now makes a new random id each time it starts, gives it with its proof, and
accepts only requests signed with the current one; after a restart Kotiko asks for a
new proof and sends the request again by itself. Update the server and the extension
together: each turns the other's older version away and says so. -
Security: a Kotiko server set to a model of its own (
LLM_MODEL), for example on a paid
provider, sent no limit on how long an answer may be, so a model that kept writing could
cost you up to the provider's own limit for one word. Every lookup now asks for at most
1,200 tokens of answer (4,000 for refreshing pronunciations), like the extension does,
in the field OpenAI expects whenLLM_URLis OpenAI's. -
Security: a web page could read your word list. It could hide a long list of words on
the page, where you'd never see them, and read back which ones Kotiko swapped. Kotiko
now swaps only words you can see: text a page hides isn't touched, and text below the
screen is swapped as you scroll to it, which also makes very long pages faster. One
visit to a page swaps at most 500 different words, each in at most 3 of your languages,
so no page can read your whole list at once. The privacy policy (version 3) says what
sites can and can't see. -
Security: any web page could switch Kotiko off on itself, and could tell that you use
Kotiko even on sites you paused, on sites Kotiko leaves alone such as banks, or with
Kotiko turned off. Where Kotiko doesn't swap, it now adds nothing to the page. -
Security: a web page could open a word's card with a fake click and search the card's
text. The card now opens only when you point at, click, tap or press a key on a word. -
Security: the popup's "This page is in …" line showed the page's own language label as
written, so a page could put any sentence it liked in Kotiko's popup. Kotiko now shows
only a language name your browser knows, and nothing otherwise. -
Security: before Kotiko sends your server's access key, the server must now show it holds
the same key, without either side sending it. Another program listening at the address
(for example while your server is stopped) never gets the key. Update your Kotiko server
along with the extension: an older server can't show it, and Kotiko says so in Settings. -
Security: after "Delete everything", Kotiko starts afresh and no longer takes an old-style
server address and token that a page's script left in the browser's storage meanwhile. -
Security: Kotiko's default server address is now
http://127.0.0.1:4747, and an address
you type ashttp://localhost:…is used as127.0.0.1, for your server and for Ollama
and LM Studio. Browsers trylocalhostat the IPv6 address[::1]first, where another
account on the same computer could listen and receive your server's access token. An
address saved aslocalhostmoves to127.0.0.1on update; nothing to do on your side. -
Security: a web page that managed to run code inside Kotiko's page script could change
Kotiko's settings, because browsers let that script write Kotiko's storage. It could turn
Kotiko off, pause sites, hide languages, change the words pages show, queue a word to be
looked up with your own AI key and saved, pick another model, or change the languages
your server's Telegram bot answers in. Kotiko now keeps the real copy of all of these
where page scripts can't reach, puts back anything changed elsewhere, and only its own
pages change settings. Nothing to do on your side; your settings move over on update.
In Firefox (and Chrome before 140), the languages you read no longer follow from
Kotiko in your other browsers: set them in each one.
Your own server
-
Self-hosted server: the two addresses that answer without your access key,
/healthand
/api/v1/proof, also answered when written another way, such as/health/or
//api/v1/proof. Now only the exact addresses do; any other spelling needs the key. -
Self-hosted server: a key written in the query of
LLM_URLorTRANSCRIBE_URL(some
providers take?key=...) was written to the log at start. The log now shows the address
without its query (https://host/v1?…), and the query's values are taken out of every
log line. A query such as?api-version=...now also reaches the provider on every
request, after the path. -
Self-hosted server behind a reverse proxy: everyone the proxy passes on was counted as
one, so a stranger sending ten wrong keys a minute could keep your other devices out
for as long as they kept at it. Set the newTRUSTED_PROXY_HEADERto the header your
proxy puts each visitor's address in (x-forwarded-for,x-real-ip,
cf-connecting-iporforwarded), and each visitor is counted on their own. The server
also recognises more of the headers proxies add (Via,X-Client-IP,
Fastly-Client-IPand others), so visitors through such a proxy are no longer taken for
your own computer, which is never limited. -
Self-hosted server: after moving your ...
Kotiko 1.0.0-rc.4
Release candidate 4 of Kotiko 1.0.0, for review and testing. It isn't sent to the stores.
To try it, unzip a zip and load the folder unpacked (Chrome: chrome://extensions, Developer mode,
Load unpacked; Firefox: about:debugging, This Firefox, Load Temporary Add-on).
Install or update
- Extension: Chrome Web Store (link added after the first review) or Firefox Add-ons (link added after the first review). Stores update installed copies on their own.
- Server (optional): in your Kotiko folder run
git pull, then restart it (./run.sh, orsystemctl --user restart kotiko). See Updating. - Extension 1.0 works with server 1.0.
Verify the files
The zips are the store packages, built from this tag; anyone can rebuild them byte for byte
(how). They contain only files from extension/ and the
license texts, no third-party code. The server's dependencies are listed in the attached CycloneDX
SBOM. Full steps, including checking the tag's signature: docs/verify.md.
sha256sum -c SHA256SUMS
gh attestation verify kotiko-chrome-1.0.0-rc.4.zip --repo ScriptKittyOS/kotiko
gh attestation verify kotiko-firefox-1.0.0-rc.4.zip --repo ScriptKittyOS/kotiko
Kotiko 1.0.0-rc.3
Release candidate 3 of Kotiko 1.0.0, for review and testing. It isn't sent to the stores.
To try it, unzip a zip and load the folder unpacked (Chrome: chrome://extensions, Developer mode,
Load unpacked; Firefox: about:debugging, This Firefox, Load Temporary Add-on).
Install or update
- Extension: Chrome Web Store (link added after the first review) or Firefox Add-ons (link added after the first review). Stores update installed copies on their own.
- Server (optional): in your Kotiko folder run
git pull, then restart it (./run.sh, orsystemctl --user restart kotiko). See Updating. - Extension 1.0 works with server 1.0.
Verify the files
The zips are the store packages, built from this tag; anyone can rebuild them byte for byte
(how). They contain only files from extension/ and the
license texts, no third-party code. The server's dependencies are listed in the attached CycloneDX
SBOM. Full steps, including checking the tag's signature: docs/verify.md.
sha256sum -c SHA256SUMS
gh attestation verify kotiko-chrome-1.0.0-rc.3.zip --repo ScriptKittyOS/kotiko
gh attestation verify kotiko-firefox-1.0.0-rc.3.zip --repo ScriptKittyOS/kotiko
Kotiko 1.0.0-rc.2
Release candidate 2 of Kotiko 1.0.0, for review and testing. It isn't sent to the stores.
To try it, unzip a zip and load the folder unpacked (Chrome: chrome://extensions, Developer mode,
Load unpacked; Firefox: about:debugging, This Firefox, Load Temporary Add-on).
Install or update
- Extension: Chrome Web Store (link added after the first review) or Firefox Add-ons (link added after the first review). Stores update installed copies on their own.
- Server (optional): in your Kotiko folder run
git pull, then restart it (./run.sh, orsystemctl --user restart kotiko). See Updating. - Extension 1.0 works with server 1.0.
Verify the files
The zips are the store packages, built from this tag; anyone can rebuild them byte for byte
(how). They contain only files from extension/ and the
license texts, no third-party code. The server's dependencies are listed in the attached CycloneDX
SBOM. Full steps, including checking the tag's signature: docs/verify.md.
sha256sum -c SHA256SUMS
gh attestation verify kotiko-chrome-1.0.0-rc.2.zip --repo ScriptKittyOS/kotiko
gh attestation verify kotiko-firefox-1.0.0-rc.2.zip --repo ScriptKittyOS/kotiko