CI / build (push) Has been cancelled
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/ - status.py: add --cleanup-done and --install-cleanup-schedule commands - Add scripts/automaton-cleanup.sh for periodic task archiving - Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders - .rules.md: add Self-Documenting UI Names rule - New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
1.2 KiB
1.2 KiB
Implementation: fix-dashboard-cors-origin
Bug
Dashboard's app.py set Access-Control-Allow-Origin: * (wildcard CORS) on all responses via CORS_HEADERS. Since the dashboard is a local single-origin app, this wildcard CORS header is unnecessary and poses a security risk — any malicious webpage on the machine could make requests to the dashboard API.
Fix
- Removed
CORS_HEADERSdictionary (which containedAccess-Control-Allow-Origin: *andAccess-Control-Allow-Methods) - Added
SECURITY_HEADERSwithX-Content-Type-Options: nosniffandX-Frame-Options: DENY - Updated
_send_json(),_send_error(), anddo_OPTIONS()to useSECURITY_HEADERSinstead ofCORS_HEADERS do_OPTIONS()no longer returnsAccess-Control-Allow-*headers — it simply returns 204 No Content
Files Changed
automaton/dashboard/ui/app.py: ReplacedCORS_HEADERSwithSECURITY_HEADERS, updated all response methodstests/test_app.py: Updated CORS-related tests to assert NOAccess-Control-Allow-Originheader is present, and that security headers are sent
Tests
test_app.pytests updated to verify security headers (X-Content-Type-Options,X-Frame-Options) and absence of CORS headers- All 249 tests pass