CI / build (push) Has been cancelled
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/ - status.py: add --cleanup-done and --install-cleanup-schedule commands - Add scripts/automaton-cleanup.sh for periodic task archiving - Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders - .rules.md: add Self-Documenting UI Names rule - New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
1.1 KiB
1.1 KiB
SPEC: Harden Dashboard Security and Fix Scripts
Goal
Close obvious security holes in the dashboard and fix script/documentation bugs identified in the audit.
Requirements
- Fix path-traversal guard in
automaton/dashboard/ui/app.py:- Replace string-prefix check with
Path.relative_toresolution.
- Replace string-prefix check with
- Tighten task name validation in the review API.
- Add uncommitted-changes warning to
scripts/update.shbefore runninggit pull. - Replace the placeholder repository URL in
README.mdandscripts/install.shwithhttp://10.37.0.86:3003/hermes/automaton. - Add guidance on atomic artifact writes to
references/stop-hook-pattern.mdor.rules.md.
Acceptance Criteria
- Path-traversal check uses robust
Pathcomparison. - Tests include path-traversal attempts.
update.shaborts or warns when local uncommitted changes exist.README.mdandinstall.shcontain the real Gitea URL.
Non-Goals
- Adding authentication to the dashboard.
- Rewriting scripts in another language.
Stop Condition
When all acceptance criteria are met, output "CONTRACT_MET".