# Spec: fix-dashboard-cors-origin ## Problem `automaton/dashboard/ui/app.py:40-44` sets `Access-Control-Allow-Origin: *` on all responses, including POST and PUT endpoints. Any website open in the user's browser can send cross-origin requests to `localhost:8080`, allowing silent modification of task reviews and config. ## Fix Remove the wildcard CORS origin. The dashboard is a local single-origin app — CORS headers are unnecessary. Either: 1. Remove `CORS_HEADERS` entirely and stop sending them, OR 2. Set `Access-Control-Allow-Origin` to `http://localhost:{port}` only Option 1 is simpler and safer. The dashboard serves both the HTML and the API from the same origin, so CORS is not needed. ## Acceptance Criteria - No `Access-Control-Allow-Origin: *` header in responses - Cross-origin requests from other websites are blocked by the browser - Same-origin dashboard HTML can still fetch the API (no CORS needed) - Existing CORS tests in `test_app.py` updated to reflect the change