Files
automaton/memory/dashboard-security.md
T

11 lines
839 B
Markdown
Raw Normal View History

# Dashboard state inference and security
## .state file is source of truth
`determine_task_state()` in `automaton/dashboard/core/task.py` must read `.state` file BEFORE falling back to artifact heuristic. Added `_state_string_to_task_state()` to map phase strings (including sub-states like `code_review:awaiting_approval`) to TaskState enum.
## No wildcard CORS on local apps
Dashboard is single-origin (serves HTML + API from same origin). `Access-Control-Allow-Origin: *` allows any malicious webpage to call the API. Remove CORS headers entirely; use `SECURITY_HEADERS` with `X-Content-Type-Options: nosniff` and `X-Frame-Options: DENY` instead.
## register-guards.sh pitfalls
Must check both `.json` and `.jsonc` opencode config files, write to `plugin` (singular) key not `plugins`, and strip `//` comments before `json.loads()`.