This build closes the wildcard CORS hole that shipped in 26.8.9. A page from another website on the same computer can no longer be told to read Fikira's local admin APIs. Study on WhatsApp stays live. This is not a claim that the student pilot is ready.
26.8.9 shipped a local server that answered every website with Access-Control-Allow-Origin star. 26.8.10 reflects only the trusted desktop renderer. Untrusted origins get no CORS header. Admin and developer routes also require a console session or a signed-in account.
Study on WhatsApp is still on for teachers, training providers, and learners. Preview, HELP, and STOP are unchanged. Parking a live channel is not a security fix, so this release does not hide that door.
If a course map has not been confirmed yet, Fikira now tells you that plainly instead of quietly serving a generic deck or failing with an error. When a course map is confirmed, the cards come from your actual course content.
Fikira no longer treats a course topic as proof of process documentation, invents Bloom verbs, or assumes an AI policy exists because a syllabus mentions AI. Unsupported claims are marked as not evidenced.
Fikira now recommends a Qwen model that fits the computer's available memory and storage. Core course analysis can run locally after setup without requiring a paid cloud AI account.
Teachers will judge whether the analysis reflects their course, identifies meaningful AI vulnerability, and supports active learning that can include appropriate uses of AI.
Teachers will assess whether Fikira's recommendations are practical, aligned with intended learning, and useful for redesigning assignments rather than simply restricting AI.
Teachers will review quizzes, flashcards, practice questions, study plans, and phone-friendly support to identify what must change before students use them.