Files
automaton/memory/dashboard-security.md
Lap Tran dd2726c0dd
CI / build (push) Has been cancelled
Add memory/ with audit findings and framework knowledge
7 memory files covering:
- audit-bug-patterns: recurring status.py bug patterns
- vram-model-matching: three-tier model prefix matching
- dashboard-security: .state priority, CORS removal, register-guards
- state-machine-workflow: legal transitions and approval gates
- testing-conventions: pytest patterns and helpers
- audit-process: report conventions and batch processing
- framework-architecture: enforcement layers and key files
2026-06-22 10:48:19 -04:00

11 lines
839 B
Markdown

# Dashboard state inference and security
## .state file is source of truth
`determine_task_state()` in `automaton/dashboard/core/task.py` must read `.state` file BEFORE falling back to artifact heuristic. Added `_state_string_to_task_state()` to map phase strings (including sub-states like `code_review:awaiting_approval`) to TaskState enum.
## No wildcard CORS on local apps
Dashboard is single-origin (serves HTML + API from same origin). `Access-Control-Allow-Origin: *` allows any malicious webpage to call the API. Remove CORS headers entirely; use `SECURITY_HEADERS` with `X-Content-Type-Options: nosniff` and `X-Frame-Options: DENY` instead.
## register-guards.sh pitfalls
Must check both `.json` and `.jsonc` opencode config files, write to `plugin` (singular) key not `plugins`, and strip `//` comments before `json.loads()`.