- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit
- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM
- Standardize all prompts to .automaton/tasks/{task-name}/ path
- Reconcile dashboard spec with web implementation; remove themes.py
- Remove half-implemented refresh.py file watcher
- Harden dashboard static-file serving and task-name validation
- Add uncommitted-change guard to update.sh and real Gitea URLs
- Add AGENTS.md, Gitea CI workflow, and template documentation
1.1 KiB
1.1 KiB
SPEC: Harden Dashboard Security and Fix Scripts
Goal
Close obvious security holes in the dashboard and fix script/documentation bugs identified in the audit.
Requirements
- Fix path-traversal guard in
automaton/dashboard/ui/app.py:- Replace string-prefix check with
Path.relative_toresolution.
- Replace string-prefix check with
- Tighten task name validation in the review API.
- Add uncommitted-changes warning to
scripts/update.shbefore runninggit pull. - Replace the placeholder repository URL in
README.mdandscripts/install.shwithhttp://10.37.0.86:3003/hermes/automaton. - Add guidance on atomic artifact writes to
references/stop-hook-pattern.mdor.rules.md.
Acceptance Criteria
- Path-traversal check uses robust
Pathcomparison. - Tests include path-traversal attempts.
update.shaborts or warns when local uncommitted changes exist.README.mdandinstall.shcontain the real Gitea URL.
Non-Goals
- Adding authentication to the dashboard.
- Rewriting scripts in another language.
Stop Condition
When all acceptance criteria are met, output "CONTRACT_MET".