Files
automaton/memory/dashboard-security.md
Lap Tran dd2726c0dd
CI / build (push) Has been cancelled
Add memory/ with audit findings and framework knowledge
7 memory files covering:
- audit-bug-patterns: recurring status.py bug patterns
- vram-model-matching: three-tier model prefix matching
- dashboard-security: .state priority, CORS removal, register-guards
- state-machine-workflow: legal transitions and approval gates
- testing-conventions: pytest patterns and helpers
- audit-process: report conventions and batch processing
- framework-architecture: enforcement layers and key files
2026-06-22 10:48:19 -04:00

839 B

Dashboard state inference and security

.state file is source of truth

determine_task_state() in automaton/dashboard/core/task.py must read .state file BEFORE falling back to artifact heuristic. Added _state_string_to_task_state() to map phase strings (including sub-states like code_review:awaiting_approval) to TaskState enum.

No wildcard CORS on local apps

Dashboard is single-origin (serves HTML + API from same origin). Access-Control-Allow-Origin: * allows any malicious webpage to call the API. Remove CORS headers entirely; use SECURITY_HEADERS with X-Content-Type-Options: nosniff and X-Frame-Options: DENY instead.

register-guards.sh pitfalls

Must check both .json and .jsonc opencode config files, write to plugin (singular) key not plugins, and strip // comments before json.loads().