# Audit: alert-dialog audit-version: 1 audited-at: 2026-06-26 scope: ['soma', 'eidos'] (composes/delegates close to Dialog; Provider is virtual) method: adversarially-verified workflow (analyze → refute); HIGH/CRITICAL personally re-verified against cited code by the lead. provider: G:\dev\svelte\vicen\src\uix\soma\components\alert-dialog\alert-dialog-provider.svelte.ts ## Summary Counts (post-verification): CRITICAL 0 · HIGH 1 · MEDIUM 0 · LOW 0. systemic hits: none. ## Findings ### HIGH: A Contract(morfo): morfo MUST be 'as const satisfies Morfo' — alert-dialog-001 - dimension: A - rule: A Contract(morfo): morfo MUST be 'as const satisfies Morfo' - location: G:\dev\svelte\vicen\src\uix\morfo\components\alert-dialog.ts:4 - evidence: export const alertDialogMorfo: Morfo = { ... } - impact: Type narrowing degraded in createAttrs; morfo loses const assertion benefits and exhaustiveness checks - repro: Build and check TypeScript diagnostics; createAttrs will not narrow string literal keys correctly - proposed-fix: Change to: export const alertDialogMorfo = { ... } as const satisfies Morfo; - verify: [confirmed] Read src/uix/morfo/components/alert-dialog.ts line 4 verbatim: `export const alertDialogMorfo: Morfo = {`. This is a bare type annotation, not the canonical `as const satisfies Morfo` form. The file ends at line 76 with `};` (no `as const satisfies Morfo` closer). Confirmed against the four baseline morfos which all use the canonical pattern: dialog.ts:15 `export const dialogMorfo = {` closing at :303 `} as const satisfies Morfo;`, popover.ts:4 closing at :251, drawer.ts:4 closing at :313, toggle.ts:22 closing at :143. The `: Morfo` annotation widens literal types (e.g. `kebab: 'alert-dialog'`, part kebabs `'provider'|'action'|'cancel'`, the `v.literal('button')` aria values) to their base types, degrading the exact-key narrowing compileMorfo/createAttrs depend on — exactly the rule-A violation described. Severity HIGH is appropriate: it is a contract-shape rule the morfo validators should catch. - fix-status: fixed (98954a7c) ## No-findings dimensions B, C, D, E, E-bis, F, G ## Theming facts (E-bis) - magic z-index: none - magic literals: none - undeclared parts: none - roles clean: true · variants clean: true ## Tests (F) - exists: true · env: jsdom - covers: action/cancel data attribute projection; aria-label resolution and reactivity; onclick close delegation to Dialog; callback execution on button click - untested: keyboard interaction (delegated to Dialog); focus trap/return (delegated to Dialog); Escape key behavior override (delegated to Dialog) ## Style observations (non-blocking) - AlertDialog properly delegates all state/focus/keyboard to Dialog with variant='alertdialog' forced - Escape key behavior override (close→ignore regression fix) is well-documented in README and implemented via wrapper - Eidos Action/Cancel properly forward dialog intent to Button via snippet binding - Action emits intent-driven color (risk→red), Cancel stays neutral—clear visual contrast matching WAI-ARIA guidance