CI / build (push) Has been cancelled
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/ - status.py: add --cleanup-done and --install-cleanup-schedule commands - Add scripts/automaton-cleanup.sh for periodic task archiving - Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders - .rules.md: add Self-Documenting UI Names rule - New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
1.1 KiB
1.1 KiB
Implementation: Harden Dashboard Security
Summary
- Added CORS headers (
Access-Control-Allow-Origin,Methods,Headers) to all API responses via_send_json()and_send_error() - Added
do_OPTIONShandler for CORS preflight requests - Added
X-Content-Type-Options: nosniffheader to all responses - Added
MAX_POST_BODY = 65536(64KB) content-length limit on POST review endpoint - Added
MAX_REVIEW_COMMENT_LENGTH = 4096character limit on review comments - Replaced inline
onclickhandlers in review buttons withdata-task/data-statusattributes + event delegation - Applied
escapeHtml()totask.display_nameinrenderTaskCard() - Filesystem task name validation was already implemented in
fix-verdict-parsing(R2 of this SPEC is done)
Changes
automaton/dashboard/ui/app.py: Added CORS headers,do_OPTIONS, content-length bounds, comment truncationautomaton/dashboard/html/dashboard.js: Replaced onclick handlers with data attributes, escaped display_name
Test Results
119 passed in 0.08s (full suite) Dashboard starts and serves correct CORS headers on all API responses
Blockers
None