You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
svelte-kit-vice/audit/components/password-field.md

4.3 KiB

Audit: password-field

audit-version: 1 audited-at: 2026-06-26 scope: (SCOPE-DRIFT → SYS-1) method: adversarially-verified workflow (analyze → refute); HIGH/CRITICAL lead-verified. Clean-check pseudo-findings dropped. B4 ground-truth: segmented date/time/color-field register inputId via $effect (SYS-A30-EFFECT, no loop); number-field is the direct-assignment reference. provider: src/uix/soma/components/password-field/password-field-provider.svelte.ts field-family (A13/A24-26/A30): A30 compliant: inputId registered directly in constructor (line 142) without $effect. Not A13 field (no hidden input required). Not A26 field (not segmented contenteditable). Not A24/A25 field (not date/range).

Summary

Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 1 · LOW 0.

Findings

MEDIUM: SCOPE-DRIFT: Eidos recipe directory exists but morfo 'scope' omits 'eidos' — password-field-001

  • dimension: B, SYS-1
  • rule: SCOPE-DRIFT: Eidos recipe directory exists but morfo 'scope' omits 'eidos'
  • location: src/uix/morfo/components/password-field.ts:31
  • evidence: scope: ['soma', 'sema'], — but eidos recipe exists at src/uix/eidos/lib/recipes/base.ts:2097 and components at src/uix/eidos/components/password-field/
  • impact: Component maintainers may miss that eidos layer exists; recipe synchronization risk if scope drift persists across the codebase
  • proposed-fix: Change line 31 to scope: ['soma', 'sema', 'eidos']
  • verify: [confirmed] CONFIRMED at the cited severity. morfo src/uix/morfo/components/password-field.ts:31 declares scope: ['soma', 'sema'], — 'eidos' is omitted. Yet eidos demonstrably implements the component: (a) the recipe entry 'password-field': { exists at src/uix/eidos/lib/recipes/base.ts:2097 (the candidate's cited line is exact), with control-height/space/font tokens following; (b) the eidos component directory src/uix/eidos/components/password-field/ contains 8 files (password-field.svelte, -input, -visibility-trigger, -strength-meter, -caps-lock-indicator, types.ts, index.ts, password-field.css). The scope field is documented in src/uix/morfo/types.ts:799 as 'Layers that implement this component', so the declared array genuinely diverges from the real implementation. This is the established SYS-1 scope-drift pattern (MEDIUM in baseline) — informational/metadata drift, not a behavioral or a11y bug: the component renders and works; the scope array does not gate eidos at runtime. MEDIUM is the correct severity (not HIGH — no latent behavioral failure; not LOW — it is a real contract/metadata inconsistency the coverage tooling tracks). Note: this is systemic, not unique to password-field — calendar (calendar.ts:7), color-field (color-field.ts:7), color-picker, combobox, command and other components likewise carry ['soma', 'sema'] while shipping eidos directories, consistent with SYS-1 being a confirmed systemic finding.
  • fix-status: open

No-findings dimensions

A Contract (Morfo), A Behavior (Soma), C DOM-selector, D Frontier, E TSC, E-bis Theming, F Tests

Theming facts (E-bis)

  • magic z-index: none
  • magic literals: z-index: 1 (line 74 password-field.css) — LOCAL subtree stacking only, acceptable per rules
  • undeclared parts: none
  • roles clean: true · variants clean: true
  • label-font (one step below input?): N/A — password-field is composable (no built-in label). Consumers use Field.Label wrapper whose font is controlled by field-level rules.

Tests (F)

  • exists: false · env: jsdom
  • covers:
  • untested: visibility toggle keydown/click; caps-lock signal on/off lifecycle (stateBound persistence); strength meter clamping and warnings flow; field integration (inputId wiring, disabled/readonly/required inheritance); validation paths (invalid state + error id describedby wiring)

Style observations (non-blocking)

  • Line 74 password-field.css: z-index: 1 is LOCAL subtree stacking (children above pseudo-element chrome), compliant per rules
  • Theming: 9 roles used correctly (primary/secondary/neutral/affirm/fulfill/risk/threat/loss); caps-indicator uses risk-track/risk-text role alias
  • Recipe tokens (font-size, spacing, radius) reference canonical CSS variables; no magic pixels/em/% drift
  • Label font rule N/A: password-field has no internal label; consumer wraps with Field.Label (font controlled at field level)

Powered by TurnKey Linux.