agentic-os/dashboard
modimihir07 a30162d114 Security audit fixes: path traversal, XSS, info disclosure, missing headers
CRITICAL fixes:
- Path traversal prevention in brain/backup/skill/file endpoints
- Unsafe tar extraction with safe_extractall() path validation

HIGH fixes:
- XSS: encodeURIComponent for onclick handlers in skills/memory/prompts/standards/backups
- XSS: escapeHtml() for user-controlled text in cost/plugins/settings/audit/dashboard
- XSS: safe class name mapping in setup-wizard (attribute injection)
- Security headers middleware (CSP, HSTS, X-Frame-Options, X-Content-Type-Options)
- CORS restricted to localhost:8080
- Settings API keys masked before returning to client
- Session replay content limited to 2000 chars + path validation

MEDIUM fixes:
- Chat message length limit (10000 chars)
- Input validation on brain/skill/backup file names (reject .. and /)
2026-06-29 13:57:44 +05:30
..
pages Security audit fixes: path traversal, XSS, info disclosure, missing headers 2026-06-29 13:57:44 +05:30
api.js v0.2.0: 7 new features + UI modernization 2026-06-05 15:22:40 +05:30
app.js Security & polish: untrack settings.json, fix CORS, remove broken og:image, replace console.error with toast 2026-05-18 01:32:24 +05:30
index.html v0.2.0: 7 new features + UI modernization 2026-06-05 15:22:40 +05:30
styles.css v0.2.0: 7 new features + UI modernization 2026-06-05 15:22:40 +05:30
utils.js v0.2.0: 7 new features + UI modernization 2026-06-05 15:22:40 +05:30