# Audit: password-field audit-version: 1 audited-at: 2026-06-26 scope: (SCOPE-DRIFT → SYS-1) method: adversarially-verified workflow (analyze → refute); HIGH/CRITICAL lead-verified. Clean-check pseudo-findings dropped. B4 ground-truth: segmented date/time/color-field register inputId via $effect (SYS-A30-EFFECT, no loop); number-field is the direct-assignment reference. provider: src/uix/soma/components/password-field/password-field-provider.svelte.ts field-family (A13/A24-26/A30): A30 compliant: inputId registered directly in constructor (line 142) without $effect. Not A13 field (no hidden input required). Not A26 field (not segmented contenteditable). Not A24/A25 field (not date/range). ## Summary Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 1 · LOW 0. ## Findings ### MEDIUM: SCOPE-DRIFT: Eidos recipe directory exists but morfo 'scope' omits 'eidos' — password-field-001 - dimension: B, SYS-1 - rule: SCOPE-DRIFT: Eidos recipe directory exists but morfo 'scope' omits 'eidos' - location: src/uix/morfo/components/password-field.ts:31 - evidence: scope: ['soma', 'sema'], — but eidos recipe exists at src/uix/eidos/lib/recipes/base.ts:2097 and components at src/uix/eidos/components/password-field/ - impact: Component maintainers may miss that eidos layer exists; recipe synchronization risk if scope drift persists across the codebase - proposed-fix: Change line 31 to scope: ['soma', 'sema', 'eidos'] - verify: [confirmed] CONFIRMED at the cited severity. morfo src/uix/morfo/components/password-field.ts:31 declares `scope: ['soma', 'sema'],` — 'eidos' is omitted. Yet eidos demonstrably implements the component: (a) the recipe entry `'password-field': {` exists at src/uix/eidos/lib/recipes/base.ts:2097 (the candidate's cited line is exact), with control-height/space/font tokens following; (b) the eidos component directory src/uix/eidos/components/password-field/ contains 8 files (password-field.svelte, -input, -visibility-trigger, -strength-meter, -caps-lock-indicator, types.ts, index.ts, password-field.css). The `scope` field is documented in src/uix/morfo/types.ts:799 as 'Layers that implement this component', so the declared array genuinely diverges from the real implementation. This is the established SYS-1 scope-drift pattern (MEDIUM in baseline) — informational/metadata drift, not a behavioral or a11y bug: the component renders and works; the `scope` array does not gate eidos at runtime. MEDIUM is the correct severity (not HIGH — no latent behavioral failure; not LOW — it is a real contract/metadata inconsistency the coverage tooling tracks). Note: this is systemic, not unique to password-field — calendar (calendar.ts:7), color-field (color-field.ts:7), color-picker, combobox, command and other components likewise carry `['soma', 'sema']` while shipping eidos directories, consistent with SYS-1 being a confirmed systemic finding. - fix-status: fixed (212624e0) ## No-findings dimensions A Contract (Morfo), A Behavior (Soma), C DOM-selector, D Frontier, E TSC, E-bis Theming, F Tests ## Theming facts (E-bis) - magic z-index: none - magic literals: z-index: 1 (line 74 password-field.css) — LOCAL subtree stacking only, acceptable per rules - undeclared parts: none - roles clean: true · variants clean: true - label-font (one step below input?): N/A — password-field is composable (no built-in label). Consumers use Field.Label wrapper whose font is controlled by field-level rules. ## Tests (F) - exists: false · env: jsdom - covers: - untested: visibility toggle keydown/click; caps-lock signal on/off lifecycle (stateBound persistence); strength meter clamping and warnings flow; field integration (inputId wiring, disabled/readonly/required inheritance); validation paths (invalid state + error id describedby wiring) ## Style observations (non-blocking) - Line 74 password-field.css: z-index: 1 is LOCAL subtree stacking (children above pseudo-element chrome), compliant per rules - Theming: 9 roles used correctly (primary/secondary/neutral/affirm/fulfill/risk/threat/loss); caps-indicator uses risk-track/risk-text role alias - Recipe tokens (font-size, spacing, radius) reference canonical CSS variables; no magic pixels/em/% drift - Label font rule N/A: password-field has no internal label; consumer wraps with Field.Label (font controlled at field level)