CI / build (push) Has been cancelled
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/ - status.py: add --cleanup-done and --install-cleanup-schedule commands - Add scripts/automaton-cleanup.sh for periodic task archiving - Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders - .rules.md: add Self-Documenting UI Names rule - New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
1.1 KiB
1.1 KiB
Code Review: fix-dashboard-cors-origin
Reviewed Files
automaton/dashboard/ui/app.py(SECURITY_HEADERS,_send_json(),_send_error(),do_OPTIONS())tests/test_app.py
Changes
Removed wildcard CORS headers (Access-Control-Allow-Origin: *), replaced with security headers (X-Content-Type-Options: nosniff, X-Frame-Options: DENY).
Analysis
- Security: Removing wildcard CORS eliminates the risk of cross-origin attacks from malicious local web pages
- Single-origin app: The dashboard is a local web app served from a single origin — CORS is unnecessary
- Security headers:
X-Content-Type-Options: nosniffprevents MIME type sniffing,X-Frame-Options: DENYprevents clickjacking - OPTIONS handler:
do_OPTIONS()still returns 204 No Content (for preflight requests) but without CORS headers - Tests: Test assertions correctly verify absence of CORS headers and presence of security headers
Verdict: PASS
The fix eliminates a security vulnerability while adding useful hardening headers. Tests are properly updated.