# Audit: pin-input audit-version: 1 audited-at: 2026-06-26 scope: method: adversarially-verified workflow (analyze → refute); HIGH/CRITICAL lead-verified. Clean-check pseudo-findings dropped. B4 ground-truth: segmented date/time/color-field register inputId via $effect (SYS-A30-EFFECT, no loop); number-field is the direct-assignment reference. provider: src/uix/soma/components/pin-input/pin-input-provider.svelte.ts field-family (A13/A24-26/A30): A13-PASS: Hidden input rendered at line 92 of src/uix/soma/components/pin-input/components/pin-input.svelte with name attribute propagated from opts.name (line 366 of provider). A30-PASS: inputId registered via direct assignment in PinInputProvider constructor (line 124 of pin-input-provider.svelte.ts), NOT $effect, matching the Field.inputId convention. Test confirms at line 136 of pin-input-prov ## Summary Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 1 · LOW 0. ## Findings ### MEDIUM: THEMING §5: Recipe font-weight tokens MUST reference --font-weight-* variables, not litera — pin-input-001 - dimension: E-bis: Theming - rule: THEMING §5: Recipe font-weight tokens MUST reference --font-weight-* variables, not literal numeric values - location: src/uix/eidos/lib/recipes/base.ts:4190 - evidence: 'cell-font-weight': '500' should be 'var(--font-weight-medium)' - impact: Decouples the pin-input cell font weight from the canonical type scale, breaking theming coherence if --font-weight-medium is ever changed - proposed-fix: Change line 4190 from "'cell-font-weight': '500'," to "'cell-font-weight': 'var(--font-weight-medium)'," - verify: [confirmed] Confirmed at src/uix/eidos/lib/recipes/base.ts:4190: the line is exactly "'cell-font-weight': '500'," — a numeric literal. The canonical token exists (generated/base.css:341: "--font-weight-medium: 500;"), so 500 maps 1:1 to --font-weight-medium and should consume the value-preserving token. This is genuine drift, not a physically-fixed value: a grep across the entire base.ts recipe file shows EVERY other font-weight declaration uses var(--font-weight-*) (e.g. lines 48, 153, 314, 1453-1457, 1669, 1686, 3670-3674, 4196 contexts), and a regex for numeric-literal font-weights ('font-weight':') matches ONLY line 4190 — it is the sole offender in the whole file. THEMING §5 / 'no magic literals — tokenize don't intentionalize' (feedback_no_intentional_magic_numbers): a literal that equals a scale step must reference the token. MEDIUM (token inconsistency / magic literal) and high confidence are both appropriate. - fix-status: open ## No-findings dimensions A: Contract (morfo), B: Behavior (soma), C: DOM-selector, D: Frontier (soma/eidos boundary), E: TSC, F: Tests, G: Redundancy ## Theming facts (E-bis) - magic z-index: none - magic literals: pin-input recipe line 4190: literal '500' for cell-font-weight - undeclared parts: none - roles clean: true · variants clean: true - label-font (one step below input?): N/A (no visible label component in morfo; soma uses aria-label on hidden input) ## Tests (F) - exists: true · env: jsdom - covers: onComplete callback firing once when value reaches length; pattern filtering on oninput; paste transformation and distribution; selection tracking and cell state derivation; focus/blur lifecycle; Field flag OR-merging (disabled, readonly, required, invalid) - untested: IME/drop edge cases (note: keydown.preventDefault alone is insufficient per A26 — but this is not a segmented input so A26 does not apply)