Archive completed tasks, add cleanup commands, self-documenting dashboard UI
CI / build (push) Has been cancelled
CI / build (push) Has been cancelled
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/ - status.py: add --cleanup-done and --install-cleanup-schedule commands - Add scripts/automaton-cleanup.sh for periodic task archiving - Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders - .rules.md: add Self-Documenting UI Names rule - New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
This commit is contained in:
@@ -1,17 +0,0 @@
|
||||
# Spec: fix-dashboard-cors-origin
|
||||
|
||||
## Problem
|
||||
`automaton/dashboard/ui/app.py:40-44` sets `Access-Control-Allow-Origin: *` on all responses, including POST and PUT endpoints. Any website open in the user's browser can send cross-origin requests to `localhost:8080`, allowing silent modification of task reviews and config.
|
||||
|
||||
## Fix
|
||||
Remove the wildcard CORS origin. The dashboard is a local single-origin app — CORS headers are unnecessary. Either:
|
||||
1. Remove `CORS_HEADERS` entirely and stop sending them, OR
|
||||
2. Set `Access-Control-Allow-Origin` to `http://localhost:{port}` only
|
||||
|
||||
Option 1 is simpler and safer. The dashboard serves both the HTML and the API from the same origin, so CORS is not needed.
|
||||
|
||||
## Acceptance Criteria
|
||||
- No `Access-Control-Allow-Origin: *` header in responses
|
||||
- Cross-origin requests from other websites are blocked by the browser
|
||||
- Same-origin dashboard HTML can still fetch the API (no CORS needed)
|
||||
- Existing CORS tests in `test_app.py` updated to reflect the change
|
||||
Reference in New Issue
Block a user