Files
automaton/tasks/harden-dashboard-security-scripts/IMPLEMENTATION.md
T
gitea 79b783864e Harden framework: tests, VRAM Python, dashboard spec, security, CI
- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit

- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM

- Standardize all prompts to .automaton/tasks/{task-name}/ path

- Reconcile dashboard spec with web implementation; remove themes.py

- Remove half-implemented refresh.py file watcher

- Harden dashboard static-file serving and task-name validation

- Add uncommitted-change guard to update.sh and real Gitea URLs

- Add AGENTS.md, Gitea CI workflow, and template documentation
2026-06-14 11:24:36 -04:00

1.3 KiB

Implementation: Harden Dashboard Security and Fix Scripts

Summary

Closed security holes in the dashboard static file serving and tightened task name validation. Fixed update.sh to warn about uncommitted changes. Replaced placeholder URLs with the real Gitea repository URL. Added artifact integrity guidance.

Files Changed

  • automaton/dashboard/ui/app.py
    • Replaced string-prefix path traversal check with robust Path.relative_to() resolution.
    • Tightened task name validation to allow only [A-Za-z0-9_-]+.
    • Added import re.
  • tests/test_app.py — added symlink path-traversal test and static-file happy-path test.
  • scripts/update.sh — added uncommitted-changes check before git pull.
  • README.md — replaced placeholder install URL with http://10.37.0.86:3003/hermes/automaton.
  • scripts/install.sh — replaced placeholder clone URL with http://10.37.0.86:3003/hermes/automaton.
  • .rules.md — added "Artifact Integrity" section with atomic-write guidance.

Verification

  • python -m pytest tests/ passes: 72 tests passed.
  • bash -n scripts/update.sh passes.
  • bash -n scripts/install.sh passes.

Decisions

  • Task names are restricted to kebab-case/alphanumeric to prevent filesystem traversal.
  • Symlinks escaping html_dir are rejected with 403.