Files
automaton/tasks/harden-dashboard-security-scripts/SPEC.md
T
gitea 79b783864e Harden framework: tests, VRAM Python, dashboard spec, security, CI
- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit

- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM

- Standardize all prompts to .automaton/tasks/{task-name}/ path

- Reconcile dashboard spec with web implementation; remove themes.py

- Remove half-implemented refresh.py file watcher

- Harden dashboard static-file serving and task-name validation

- Add uncommitted-change guard to update.sh and real Gitea URLs

- Add AGENTS.md, Gitea CI workflow, and template documentation
2026-06-14 11:24:36 -04:00

1.1 KiB

SPEC: Harden Dashboard Security and Fix Scripts

Goal

Close obvious security holes in the dashboard and fix script/documentation bugs identified in the audit.

Requirements

  1. Fix path-traversal guard in automaton/dashboard/ui/app.py:
    • Replace string-prefix check with Path.relative_to resolution.
  2. Tighten task name validation in the review API.
  3. Add uncommitted-changes warning to scripts/update.sh before running git pull.
  4. Replace the placeholder repository URL in README.md and scripts/install.sh with http://10.37.0.86:3003/hermes/automaton.
  5. Add guidance on atomic artifact writes to references/stop-hook-pattern.md or .rules.md.

Acceptance Criteria

  • Path-traversal check uses robust Path comparison.
  • Tests include path-traversal attempts.
  • update.sh aborts or warns when local uncommitted changes exist.
  • README.md and install.sh contain the real Gitea URL.

Non-Goals

  • Adding authentication to the dashboard.
  • Rewriting scripts in another language.

Stop Condition

When all acceptance criteria are met, output "CONTRACT_MET".