- **Restore 82 completed tasks** from tasks/complete/ back to tasks/ top level (all <7 days old per the cleanup policy; premature bulk archive was fixed). - **Dashboard: fix scroll-reset on auto-refresh** — renderBoard rebuilds the board via innerHTML every 2s, destroying each column-body's scrollTop. Now snapshots column-body scrollTop + board.scrollLeft + view.scrollTop before rebuild and restores after (matched by PHASE_GROUPS index). - **Dashboard UI additions** (pre-existing unstaged work): approval section cards, transition buttons, inline artifact editor (textarea for writing missing SPEC/VERDICT/etc from the detail modal). - **Bind ornith as Implement model** — config.md: Model explicit to omlx/Ornith-1.0-35B-4bit-mlx, context window 32768. Interactive autopilot already used ornith via opencode default; now explicit. - **Fix cleanup stub** — automaton-cleanup.sh had a stale --project arg pointing at a pytest temp dir (test isolation leak). Rewired to point at ~/.automaton. - **Fix plist-isolation test** — test asserted host plist doesn't exist, but a real install creates it. Now snapshots mtime before run, asserts unchanged after (only a write during the test counts as bleed). - **New Playwright smoke test** (tests/test_dashboard_ui.py) — 2 tests: board renders tasks, column scroll survives auto-refresh tick. Verified the test fails without the scroll fix (scrollTop resets to 0). Skipped via importorskip when playwright is absent (main CI stays green). - **Clarify SI loop scope in README** — new-project onboarding section documents the framework-scoped self-improvement loop and options (leave/pause/create project loop). - **CHANGELOG** documents all changes including the known model-divergence gap (mde tasks marked complete but per-role model binding was never implemented).
1.3 KiB
1.3 KiB
Implementation: Harden Dashboard Security and Fix Scripts
Summary
Closed security holes in the dashboard static file serving and tightened task name validation. Fixed update.sh to warn about uncommitted changes. Replaced placeholder URLs with the real Gitea repository URL. Added artifact integrity guidance.
Files Changed
automaton/dashboard/ui/app.py- Replaced string-prefix path traversal check with robust
Path.relative_to()resolution. - Tightened task name validation to allow only
[A-Za-z0-9_-]+. - Added
import re.
- Replaced string-prefix path traversal check with robust
tests/test_app.py— added symlink path-traversal test and static-file happy-path test.scripts/update.sh— added uncommitted-changes check beforegit pull.README.md— replaced placeholder install URL withhttp://10.37.0.86:3003/hermes/automaton.scripts/install.sh— replaced placeholder clone URL withhttp://10.37.0.86:3003/hermes/automaton..rules.md— added "Artifact Integrity" section with atomic-write guidance.
Verification
python -m pytest tests/passes: 72 tests passed.bash -n scripts/update.shpasses.bash -n scripts/install.shpasses.
Decisions
- Task names are restricted to kebab-case/alphanumeric to prevent filesystem traversal.
- Symlinks escaping
html_dirare rejected with 403.