CI / build (push) Has been cancelled
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/ - status.py: add --cleanup-done and --install-cleanup-schedule commands - Add scripts/automaton-cleanup.sh for periodic task archiving - Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders - .rules.md: add Self-Documenting UI Names rule - New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
995 B
995 B
Spec: fix-dashboard-cors-origin
Problem
automaton/dashboard/ui/app.py:40-44 sets Access-Control-Allow-Origin: * on all responses, including POST and PUT endpoints. Any website open in the user's browser can send cross-origin requests to localhost:8080, allowing silent modification of task reviews and config.
Fix
Remove the wildcard CORS origin. The dashboard is a local single-origin app — CORS headers are unnecessary. Either:
- Remove
CORS_HEADERSentirely and stop sending them, OR - Set
Access-Control-Allow-Origintohttp://localhost:{port}only
Option 1 is simpler and safer. The dashboard serves both the HTML and the API from the same origin, so CORS is not needed.
Acceptance Criteria
- No
Access-Control-Allow-Origin: *header in responses - Cross-origin requests from other websites are blocked by the browser
- Same-origin dashboard HTML can still fetch the API (no CORS needed)
- Existing CORS tests in
test_app.pyupdated to reflect the change