Files
automaton/tasks/complete/harden-dashboard-security-scripts/IMPLEMENTATION.md
T
Lap Tran 4a2301b077
CI / build (push) Has been cancelled
Archive completed tasks, add cleanup commands, self-documenting dashboard UI
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/
- status.py: add --cleanup-done and --install-cleanup-schedule commands
- Add scripts/automaton-cleanup.sh for periodic task archiving
- Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders
- .rules.md: add Self-Documenting UI Names rule
- New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
2026-06-24 22:43:33 -04:00

1.3 KiB

Implementation: Harden Dashboard Security and Fix Scripts

Summary

Closed security holes in the dashboard static file serving and tightened task name validation. Fixed update.sh to warn about uncommitted changes. Replaced placeholder URLs with the real Gitea repository URL. Added artifact integrity guidance.

Files Changed

  • automaton/dashboard/ui/app.py
    • Replaced string-prefix path traversal check with robust Path.relative_to() resolution.
    • Tightened task name validation to allow only [A-Za-z0-9_-]+.
    • Added import re.
  • tests/test_app.py — added symlink path-traversal test and static-file happy-path test.
  • scripts/update.sh — added uncommitted-changes check before git pull.
  • README.md — replaced placeholder install URL with http://10.37.0.86:3003/hermes/automaton.
  • scripts/install.sh — replaced placeholder clone URL with http://10.37.0.86:3003/hermes/automaton.
  • .rules.md — added "Artifact Integrity" section with atomic-write guidance.

Verification

  • python -m pytest tests/ passes: 72 tests passed.
  • bash -n scripts/update.sh passes.
  • bash -n scripts/install.sh passes.

Decisions

  • Task names are restricted to kebab-case/alphanumeric to prevent filesystem traversal.
  • Symlinks escaping html_dir are rejected with 403.