Files
automaton/tasks/complete/harden-dashboard-security-scripts/SPEC.md
T
Lap Tran 4a2301b077
CI / build (push) Has been cancelled
Archive completed tasks, add cleanup commands, self-documenting dashboard UI
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/
- status.py: add --cleanup-done and --install-cleanup-schedule commands
- Add scripts/automaton-cleanup.sh for periodic task archiving
- Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders
- .rules.md: add Self-Documenting UI Names rule
- New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
2026-06-24 22:43:33 -04:00

1.1 KiB

SPEC: Harden Dashboard Security and Fix Scripts

Goal

Close obvious security holes in the dashboard and fix script/documentation bugs identified in the audit.

Requirements

  1. Fix path-traversal guard in automaton/dashboard/ui/app.py:
    • Replace string-prefix check with Path.relative_to resolution.
  2. Tighten task name validation in the review API.
  3. Add uncommitted-changes warning to scripts/update.sh before running git pull.
  4. Replace the placeholder repository URL in README.md and scripts/install.sh with http://10.37.0.86:3003/hermes/automaton.
  5. Add guidance on atomic artifact writes to references/stop-hook-pattern.md or .rules.md.

Acceptance Criteria

  • Path-traversal check uses robust Path comparison.
  • Tests include path-traversal attempts.
  • update.sh aborts or warns when local uncommitted changes exist.
  • README.md and install.sh contain the real Gitea URL.

Non-Goals

  • Adding authentication to the dashboard.
  • Rewriting scripts in another language.

Stop Condition

When all acceptance criteria are met, output "CONTRACT_MET".