- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit
- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM
- Standardize all prompts to .automaton/tasks/{task-name}/ path
- Reconcile dashboard spec with web implementation; remove themes.py
- Remove half-implemented refresh.py file watcher
- Harden dashboard static-file serving and task-name validation
- Add uncommitted-change guard to update.sh and real Gitea URLs
- Add AGENTS.md, Gitea CI workflow, and template documentation
653 B
653 B
Verdict: Harden Dashboard Security and Fix Scripts
Status: PASS
Completion Date: 2026-06-14
Summary
Dashboard static file serving now uses a robust path containment check, task names are strictly validated, update.sh protects against overwriting local changes, and repository URLs point to the real Gitea instance.
Findings
- Path traversal check uses
Path.relative_to(). - Task name regex rejects special characters and path separators.
update.shaborts on uncommitted changes.- README and install script contain the real Gitea URL.
- Atomic-write guidance added to
.rules.md.
Remaining Issues
None.
Score
+10 PASS