Fix 10 audit bugs: path prefix matching, verdict parsing, CORS, stale-task detection, phase mapping
CI / build (push) Has been cancelled
CI / build (push) Has been cancelled
Batch 1 (High severity): - Bug 1: --audit cat3 now checks .automaton/tasks/ paths - Bug 4: Verdict PASS/FAIL uses structured ## Status: line parsing - Bug 5: register-guards.sh checks .json/.jsonc, writes plugin key, strips comments - Bug 7: --can-edit/--scope-check path prefix uses os.sep boundary Batch 2 (Medium/Low severity): - Bug 2: migrate-project.sh find command parentheses for -prune binding - Bug 3: vram_detect model prefix matching with known-suffix whitelist - Bug 6: dashboard reads .state file before artifact heuristic fallback - Bug 8: removed wildcard CORS, added security headers (nosniff, DENY) - Bug 9: stale-task detection uses .state.lastedit instead of .state mtime - Bug 10: TEST_PLAN.md maps to test_design (was implement) 249 tests pass (up from 235). All 10 tasks driven through full workflow to completion.
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
# Spec: fix-dashboard-read-state
|
||||
|
||||
## Problem
|
||||
`automaton/dashboard/core/task.py:462` (`determine_task_state`) infers task phase purely from artifact files, never reading the `.state` file. This contradicts `prompts/workflow.md` which declares `.state` as the "single source of truth." The dashboard cannot reflect the actual enforced state.
|
||||
|
||||
## Fix
|
||||
Read the `.state` file first in `determine_task_state()`. If `.state` exists, parse the phase and map it to a `TaskState`. Fall back to artifact heuristics only if `.state` doesn't exist (pre-v2.0 tasks).
|
||||
|
||||
The phase string in `.state` may include substates like `research:awaiting_approval` — map these to their base phase (`research`).
|
||||
|
||||
## Acceptance Criteria
|
||||
- A task in `implement` phase (per `.state`) shows as `IMPLEMENT` in the dashboard even without IMPLEMENTATION.md
|
||||
- A task in `test_design` phase shows as `TEST_DESIGN`, not `IMPLEMENT`
|
||||
- A task without `.state` still uses artifact heuristics (backward compat)
|
||||
- Existing dashboard tests in `test_task.py` still pass
|
||||
- Add test verifying `.state` takes precedence over artifacts
|
||||
Reference in New Issue
Block a user