Files
automaton/tasks/dashboard-task-review/ADVERSARIAL_BUG_REPORT.md
T
gitea b15b495d2e Close all 10 tasks through full lifecycle (Implementation → Bug Find → Adversarial → Doc Review → Referee)
- Drive all approved tasks to completion with VERDICT.md
- Fix state machine: IMPLEMENTATION.md was never checked in determine_task_state()
- Fix state machine: DOC_REVIEW.md priority wrong (checked after BUG_REPORT)
- Fix board display: approved planning tasks now advance to Design group
- Fix board display: rejected planning tasks move to Blocked group
- Fix path traversal: review API validated task names against ../ injection
- Fix URL encoding: unquote() task names in API path parsing
- Fix comment parsing: robust REVIEW.md read/write, handle falsy comments
- Fix dead code: KanbanBoard class missing COLUMNS and __init__
- Fix inotify: explicit error messages and polling fallback
- Fix review API: validate task names, prevent path traversal
- Update CHANGELOG.md with all changes
2026-06-13 21:09:57 -04:00

1.2 KiB

Adversarial Bug Report: Dashboard Task Review and Approval

Deep Review

The review API writes REVIEW.md to the task folder. Submissions are POST with status + comment.

Potential Issues

  1. No authentication: Any HTTP client can submit reviews. The dashboard is localhost-only by default, but --host 0.0.0.0 exposes the review API without auth.

  2. No CSRF protection: POST endpoint accepts JSON from any origin. Mitigated by same-origin policy and no cookies/auth.

  3. Path traversal in task name: Task name is URL-decoded but no ../ check. An attacker could write REVIEW.md outside the tasks directory. Fixed below.

  4. Comment injection: Comment content is written directly to REVIEW.md without escaping. If REVIEW.md is ever consumed by a markdown renderer, injected markdown could be an issue.

Security Fix: Path traversal

The _handle_review endpoint writes to project_root / ".automaton" / "tasks" / task_name / self.REVIEW_FILE. If task_name contains ../, the review file could be written outside the tasks directory. Add a path traversal check.

Security Fix Applied

Added path traversal validation to task name in _handle_review and _get_review_status.

Verdict: PASS (with security fix applied)