CI / build (push) Has been cancelled
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/ - status.py: add --cleanup-done and --install-cleanup-schedule commands - Add scripts/automaton-cleanup.sh for periodic task archiving - Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders - .rules.md: add Self-Documenting UI Names rule - New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
1.3 KiB
1.3 KiB
Implementation: Harden Dashboard Security and Fix Scripts
Summary
Closed security holes in the dashboard static file serving and tightened task name validation. Fixed update.sh to warn about uncommitted changes. Replaced placeholder URLs with the real Gitea repository URL. Added artifact integrity guidance.
Files Changed
automaton/dashboard/ui/app.py- Replaced string-prefix path traversal check with robust
Path.relative_to()resolution. - Tightened task name validation to allow only
[A-Za-z0-9_-]+. - Added
import re.
- Replaced string-prefix path traversal check with robust
tests/test_app.py— added symlink path-traversal test and static-file happy-path test.scripts/update.sh— added uncommitted-changes check beforegit pull.README.md— replaced placeholder install URL withhttp://10.37.0.86:3003/hermes/automaton.scripts/install.sh— replaced placeholder clone URL withhttp://10.37.0.86:3003/hermes/automaton..rules.md— added "Artifact Integrity" section with atomic-write guidance.
Verification
python -m pytest tests/passes: 72 tests passed.bash -n scripts/update.shpasses.bash -n scripts/install.shpasses.
Decisions
- Task names are restricted to kebab-case/alphanumeric to prevent filesystem traversal.
- Symlinks escaping
html_dirare rejected with 403.