- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit
- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM
- Standardize all prompts to .automaton/tasks/{task-name}/ path
- Reconcile dashboard spec with web implementation; remove themes.py
- Remove half-implemented refresh.py file watcher
- Harden dashboard static-file serving and task-name validation
- Add uncommitted-change guard to update.sh and real Gitea URLs
- Add AGENTS.md, Gitea CI workflow, and template documentation
1.3 KiB
1.3 KiB
Implementation: Harden Dashboard Security and Fix Scripts
Summary
Closed security holes in the dashboard static file serving and tightened task name validation. Fixed update.sh to warn about uncommitted changes. Replaced placeholder URLs with the real Gitea repository URL. Added artifact integrity guidance.
Files Changed
automaton/dashboard/ui/app.py- Replaced string-prefix path traversal check with robust
Path.relative_to()resolution. - Tightened task name validation to allow only
[A-Za-z0-9_-]+. - Added
import re.
- Replaced string-prefix path traversal check with robust
tests/test_app.py— added symlink path-traversal test and static-file happy-path test.scripts/update.sh— added uncommitted-changes check beforegit pull.README.md— replaced placeholder install URL withhttp://10.37.0.86:3003/hermes/automaton.scripts/install.sh— replaced placeholder clone URL withhttp://10.37.0.86:3003/hermes/automaton..rules.md— added "Artifact Integrity" section with atomic-write guidance.
Verification
python -m pytest tests/passes: 72 tests passed.bash -n scripts/update.shpasses.bash -n scripts/install.shpasses.
Decisions
- Task names are restricted to kebab-case/alphanumeric to prevent filesystem traversal.
- Symlinks escaping
html_dirare rejected with 403.