Files
automaton/tasks/complete/fix-dashboard-cors-origin/SPEC.md
T
Lap Tran 4a2301b077
CI / build (push) Has been cancelled
Archive completed tasks, add cleanup commands, self-documenting dashboard UI
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/
- status.py: add --cleanup-done and --install-cleanup-schedule commands
- Add scripts/automaton-cleanup.sh for periodic task archiving
- Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders
- .rules.md: add Self-Documenting UI Names rule
- New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
2026-06-24 22:43:33 -04:00

995 B

Spec: fix-dashboard-cors-origin

Problem

automaton/dashboard/ui/app.py:40-44 sets Access-Control-Allow-Origin: * on all responses, including POST and PUT endpoints. Any website open in the user's browser can send cross-origin requests to localhost:8080, allowing silent modification of task reviews and config.

Fix

Remove the wildcard CORS origin. The dashboard is a local single-origin app — CORS headers are unnecessary. Either:

  1. Remove CORS_HEADERS entirely and stop sending them, OR
  2. Set Access-Control-Allow-Origin to http://localhost:{port} only

Option 1 is simpler and safer. The dashboard serves both the HTML and the API from the same origin, so CORS is not needed.

Acceptance Criteria

  • No Access-Control-Allow-Origin: * header in responses
  • Cross-origin requests from other websites are blocked by the browser
  • Same-origin dashboard HTML can still fetch the API (no CORS needed)
  • Existing CORS tests in test_app.py updated to reflect the change