Files
automaton/tasks/complete/harden-dashboard-security/IMPLEMENTATION.md
T
Lap Tran 4a2301b077
CI / build (push) Has been cancelled
Archive completed tasks, add cleanup commands, self-documenting dashboard UI
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/
- status.py: add --cleanup-done and --install-cleanup-schedule commands
- Add scripts/automaton-cleanup.sh for periodic task archiving
- Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders
- .rules.md: add Self-Documenting UI Names rule
- New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
2026-06-24 22:43:33 -04:00

1.1 KiB

Implementation: Harden Dashboard Security

Summary

  • Added CORS headers (Access-Control-Allow-Origin, Methods, Headers) to all API responses via _send_json() and _send_error()
  • Added do_OPTIONS handler for CORS preflight requests
  • Added X-Content-Type-Options: nosniff header to all responses
  • Added MAX_POST_BODY = 65536 (64KB) content-length limit on POST review endpoint
  • Added MAX_REVIEW_COMMENT_LENGTH = 4096 character limit on review comments
  • Replaced inline onclick handlers in review buttons with data-task/data-status attributes + event delegation
  • Applied escapeHtml() to task.display_name in renderTaskCard()
  • Filesystem task name validation was already implemented in fix-verdict-parsing (R2 of this SPEC is done)

Changes

  • automaton/dashboard/ui/app.py: Added CORS headers, do_OPTIONS, content-length bounds, comment truncation
  • automaton/dashboard/html/dashboard.js: Replaced onclick handlers with data attributes, escaped display_name

Test Results

119 passed in 0.08s (full suite) Dashboard starts and serves correct CORS headers on all API responses

Blockers

None