Changes
PR #2107 by johnpippett: Security: fix remote file write and shell injection in template extensions
- Fixed a remote arbitrary file write vulnerability by disabling automatic application of file changes when running in API mode, preventing unsupervised writes triggered through the REST API's
PatternNameinput. - Replaced the weak
strings.Contains(path, "..")check in the file manager with proper path containment validation that rejects absolute paths and confirms resolved paths stay within the project root. - Hardened the path containment check in
ApplyFileChangesby usingfilepath.Rel, correctly handling edge cases such as a project root of/. - Consolidated path validation in
ParseFileChangesandApplyFileChangesto a singlefilepath.IsLocalcall, which rejects absolute paths, empty paths, directory traversal, and Windows reserved names. - Added a regression test that fails if the path containment guard is removed.
PR #2187 by moritzschmitz-oviva: feat: add Eisenhower Matrix prioritization pattern
- Added a new Eisenhower Matrix prioritization pattern for task triage and decision-making.
- Renamed the pattern from
eisenhowertoeisenhower_matrixand removed the old pattern directory. - Relocated the Eisenhower Matrix pattern into
data/patterns. - Registered the pattern's description and metadata with the BUSINESS, SELF, and STRATEGY tags.
- Added task classification and a weekly planning extract to the pattern.