docs(pendientes): close Kim Round 3 — item 28 done, items 19-24/27/29 deferred

Closes Kim Round 3 item 28: replace phantom `defaultCalculateStrength`
identifier in PasswordField docblocks with the actual export name
(`passwordStrength` from `$libs/secs`, aliased as `calculateStrength`
when the option is omitted). Docblocks in `password-field-provider.svelte.ts`
and `types.ts` no longer reference a non-existent symbol.

Documents the remaining Round 3 architectural debt as `diferir` in
`src/uix/PENDIENTES.md` under a new "Kim audit Round 3 — deuda
arquitectónica restante" section:

  §3 Code duplication (no contract test catches these):
    - FloatingShellProvider factory (~600 lines across 15 providers)
    - BaseSegmentProvider (date-field 1674 + time-field 1072,
      ~300 duplicated)
    - ListSelectionHelper (combobox + select, ~80 duplicated)
    - DateFieldProvider.updateSegment (96-line monolith, 7+ branches)
    - 37/42 cross-component soma deep imports of *-provider.svelte
    - Redundant $effects in date-field, time-field, drawer, command

  §6 Greenfield guardrails on brownfield code:
    - Contract tests force final-state strictness on transitional code.
      Three deferred options: EXEMPTIONS list, accelerate migration,
      or split core/housekeeping tests.

  §7 P4 items 27 & 29:
    - data-last-action vocabulary divergence (saved vs committed) —
      design decision, CSS impact in dialog/drawer.
    - SEMA_VERBS expansion — needs prior audit of declared vs used.

Test result unchanged: 2391/2397 passing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
active-uix
dev 5 months ago
parent d4e668b234
commit 00cd3a2c61

@ -104,6 +104,36 @@ quitar `preload-data` del rail (10 minutos, ganancia inmediata) → fijar
por componente (1-2 días, gana el grueso del transfer) → sema/langs por componente (1-2 días, gana el grueso del transfer) → sema/langs
lazy registration (sprint propio). lazy registration (sprint propio).
## Kim audit Round 3 — deuda arquitectónica restante
Cerrados de Round 3 (en commits previos esta sesión): §2 context.ts
revert (`d4e668b2`), item 28 `defaultCalculateStrength` referencia
fantasma. Lo siguiente queda **diferir** hasta sprint de refactor.
### §3 · Duplicación de código (sin contracto que la detecte)
| Item | Disposición |
| --- | --- |
| **FloatingShellProvider factory** — el setup `FloatingProvider.create + Presence + FloatingContent.create` está copia-pegado en 15 providers (popover, dropdown-menu, combobox, select, tooltip, context-menu, 5 pickers, link-preview, menubar). Cada uno repite ~40-60 líneas. Total: ~600 líneas duplicadas (18 matches confirmados via grep). | **diferir** — refactor grande de alto valor pero alto riesgo (15 archivos críticos). Sprint propio. |
| **BaseSegmentProvider** (date-field 1674 líneas, time-field 1072 líneas). Ambos tienen `BaseNumericSegmentProvider` / `BaseTimeNumericSegmentProvider` con `updateSegment`, `handleNumberKey`, `handleBackspace`, `handleArrowUp/Down`, `onfocusout` y `SEGMENT_CONFIGS` estructuralmente idénticos. Plus `DayPeriod`, `Literal`, `TimeZone` casi byte-idénticas. ~300 líneas duplicadas. | **diferir** — extraer base abstracta genérica sobre `<TProvider, TPart>`. Las firmas divergen un poco (`formatValue` con/sin `forDisplay`, `getAnnouncement` en date no en time) — reconciliarlas requiere decisión cuidadosa. |
| **ListSelectionHelper** (combobox 1091 líneas + select). `selectItem` con modo single/multi, `allowDeselect`, `handleClose`, trigger de eventos ~80 líneas duplicadas. Combobox sólo añade `inputValue` sync. | **diferir** — abstracción de tamaño medio, valor visible. |
| **`DateFieldProvider.updateSegment`** — método monolítico, 96 líneas, 7+ ramas if. | **diferir** — partir en helpers por segment kind. |
| **24 imports directos de `../field/field-provider.svelte`** (en realidad 37 de 42 cross-component soma imports). No es violación de capa (soma→soma) sino inconsistencia: el patrón canónico es importar la clase desde el barrel del componente vía `internals.ts`. | **diferir** — cosmético, alto coste (tocar 37 archivos) sin cambio behavioral. |
| **`$effect` redundantes** en date-field, time-field, drawer, command — el audit sugiere mergear cascadas reactivas que comparten dependencias. | **diferir** — caso por caso, lectura cuidadosa requerida. |
### §6 · Greenfield guardrails on brownfield code
| Item | Disposición |
| --- | --- |
| Los tests de contrato (`contracts.test.ts`, `recipe-css-contract.test.ts`, `component-api-contract.test.ts`) fuerzan estado final prístino mientras el código sigue migrándose. Actualmente 6 fallos remanentes son todos Words/cookie-infra. Cuando aparezca un componente transicional en estado intermedio, los tests bloquean. | **diferir** — tres opciones a evaluar cuando aplique: (A) lista `EXEMPTIONS` con fechas objetivo, (B) acelerar migración, (C) split tests en "core infra" (debe pasar) vs "housekeeping" (failures conocidos trackeados). |
### §7 P4 · Items menores no abordados
| Item | Disposición |
| --- | --- |
| **Item 27 · `data-last-action` vocabulario divergente** — dialog/drawer usan `'saved'`, pickers usan `'committed'` / `'range-committed'`. CSS de salida en `dialog.css` + `drawer.css` selecciona sobre `[data-last-action='saved']`. Cambiarlo rompe esas reglas. | **diferir + decisión** — los dos nombres son semánticamente distintos (form-persist vs value-commit). Si se unifica, el side seleccionado debe documentarse como canónico y propagarse a las 4-6 morfos + 2-4 CSS afectadas. |
| **Item 29 · `SEMA_VERBS` expansion** — el audit sugiere que la lista actual de verbos canónicos no cubre toda la superficie de morfos existente. Requiere auditoría de verbos usados vs declarados. | **diferir** — investigación previa necesaria para concretar scope. |
## Doc debt ## Doc debt
| Item | Disposición | | Item | Disposición |

@ -169,8 +169,9 @@ export class PasswordFieldProvider {
* algorithm once and exposes the normalized result. `derivedStrength` * algorithm once and exposes the normalized result. `derivedStrength`
* and `derivedWarnings` are thin projections of this. * and `derivedWarnings` are thin projections of this.
* *
* The default algorithm (`defaultCalculateStrength`) returns the * The default algorithm — `passwordStrength` from `$libs/secs`,
* canonical `PasswordStrengthResult` from `$libs/secs` with warning * aliased to `calculateStrength` when the option is omitted —
* returns the canonical `PasswordStrengthResult` with warning
* LangRef strings the consumer can translate via `langs.ts(...)`. * LangRef strings the consumer can translate via `langs.ts(...)`.
*/ */
readonly derivedResult = $derived.by(() => readonly derivedResult = $derived.by(() =>

@ -106,7 +106,7 @@ export type PasswordFieldProps = WithChild<
* *
* Override with zxcvbn, OWASP NIST 800-63B, server-side scoring, etc. * Override with zxcvbn, OWASP NIST 800-63B, server-side scoring, etc.
* *
* @default defaultCalculateStrength — delegates to `passwordStrength` from `$libs/secs` * @default `passwordStrength` from `$libs/secs` (aliased internally as `calculateStrength`)
*/ */
calculateStrength?: (pw: string) => number | PasswordStrengthResult; calculateStrength?: (pw: string) => number | PasswordStrengthResult;

Loading…
Cancel
Save

Powered by TurnKey Linux.