You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
31 lines
2.1 KiB
31 lines
2.1 KiB
|
3 months ago
|
# Audit: button
|
||
|
|
audit-version: 1
|
||
|
|
audited-at: 2026-06-26
|
||
|
|
scope: soma,sema,eidos
|
||
|
|
method: adversarially-verified workflow; HIGH lead-verified. B7 ground-truth: Toolbar A35 + Form A36 incidents STAYED FIXED (untrack present); toast/clipboard/drag-drop use uix.timers (no A6 leak); button is clean (its archetype finding was inert — Spinner not runtime-registered); data-size/data-shape are eidos visual attrs (not contract violations).
|
||
|
|
provider: /g/dev/svelte/vicen/src/uix/soma/components/button/button-provider.svelte.ts
|
||
|
|
cleanup-audit (A6/A35/A36): No timers, listeners, observers, or cleanup needed. ButtonProvider uses no setTimeout, setInterval, ResizeObserver, IntersectionObserver, MutationObserver, or other disposable resources. All state is reactive via $derived.by() with no effect roots. No $effect blocks with side effects. A35/A36 loop c
|
||
|
|
|
||
|
|
## Summary
|
||
|
|
Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 0 · LOW 0.
|
||
|
|
|
||
|
|
## Findings
|
||
|
|
_No findings survived verification (clean component)._
|
||
|
|
|
||
|
|
## No-findings dimensions
|
||
|
|
B, C, D, F, G
|
||
|
|
|
||
|
|
## Theming facts (E-bis)
|
||
|
|
- magic z-index: none
|
||
|
|
- magic literals: none
|
||
|
|
- undeclared parts: none
|
||
|
|
- roles clean: true · variants clean: true
|
||
|
|
|
||
|
|
## Tests (F)
|
||
|
|
- exists: false · env: N/A
|
||
|
|
- covers:
|
||
|
|
- untested: ButtonProvider initialization and onclick flow; Intent → color cascade resolution (intent wins over color, neutral fallback); Field provider OR-merge of disabled state; Loading state gating of contact-activate event; onPress callback invocation; data-color, data-loading, data-disabled attribute synchronization
|
||
|
|
|
||
|
|
## Style observations (non-blocking)
|
||
|
|
- Focus-ring implementation (button.css 99-107) correctly uses outline with --focus-ring-* tokens and does NOT hardcode any two-ring composite — single primary-tinted ring is intentional per comment. :active (button.css 90-97) correctly uses scale(var(--press-scale)) with canonical press tokens, not a hardcoded translateY. Variant slice pattern (158-212) uniformly applies via palette variables for soft/surface/outline/ghost/plain — no per-variant hardcoding. Icon sizing correctly feeds --icon-size from --_button-icon-size which cascades per size (lines 30-35, 111-154).
|