You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
5.2 KiB
5.2 KiB
Audit: color-field
audit-version: 1 audited-at: 2026-06-26 scope: ['soma', 'sema'] (SCOPE-DRIFT → SYS-1) method: adversarially-verified workflow (analyze → refute); HIGH/CRITICAL lead-verified. Clean-check pseudo-findings dropped. B4 ground-truth: segmented date/time/color-field register inputId via $effect (SYS-A30-EFFECT, no loop); number-field is the direct-assignment reference. provider: G:/dev/svelte/vicen/src/uix/soma/components/color-field/color-field-provider.svelte.ts
Summary
Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 2 · LOW 0.
Findings
MEDIUM: SYS-1: morfo scope declares eidos layer when eidos recipe dir exists — color-field-001
- dimension: Frontier
- rule: SYS-1: morfo scope declares eidos layer when eidos recipe dir exists
- location: src/uix/morfo/components/color-field.ts:7
- evidence: scope: ['soma', 'sema'], but src/uix/eidos/components/color-field/ directory exists with 9 files (color-field.svelte, color-field.css, types.ts, etc.)
- impact: Contract drift: callers may assume eidos layer is not provided; scope-drift masks available visual customization surface.
- proposed-fix: Add 'eidos' to scope declaration: scope: ['soma', 'sema', 'eidos']
- verify: [confirmed] Confirmed SYS-1 scope-drift. morfo/components/color-field.ts:7
scope: ['soma', 'sema'],omits 'eidos'; eidos dir src/uix/eidos/components/color-field/ exists with real color-field.css (10039 bytes) + recipe. MEDIUM correct. Systemic across field family (css/date/number/password/search/time-field all do the same). - fix-status: fixed (
212624e0)
MEDIUM: F: test coverage misses high-risk readonly-segments + value=undefined path — color-field-002
- dimension: Tests
- rule: F: test coverage misses high-risk readonly-segments + value=undefined path
- location: src/uix/soma/components/color-field/color-field-provider.svelte.test.ts:94-258
- evidence: Test suite covers: segment fills (lines 100-123), keyboard hex input (125-155), format switching (157-188), wiring (190-257). Missing: readonly-segment-without-value warning assertion (defined in soma at lines 215-233) and edge cases like backspace, Home/End navigation, readonly interaction.
- impact: A24 warning logic is unexercised; regressions in readonlySegments guard logic could slip through. readonly-segment test is a HIGH-RISK gap per audit rules.
- proposed-fix: Add test case: 'warns when readonlySegments set without value' — assert soma.logger.warn is called with expected message. Add test for backspace on first segment (moveToPrev).
- verify: [confirmed] Confirmed. Provider warning at color-field-provider.svelte.ts:215-233 (spam-guarded via lastWarnedKey, calls soma.logger.warn for readonlySegments set + value undefined) is unexercised: test only mocks
warn: vi.fn()(line 46) and seeds emptyreadonlySegments(line 76). No assertion, no non-empty+undefined case. A24 high-risk path missing test = MEDIUM. - fix-status: open
MEDIUM: A30 — inputId registered via $effect instead of direct constructor assignment (SYSTEMIC: date/time/color-field)
- dimension: B
- rule: A30 (child→parent id registration MUST be a direct constructor assignment, not
$effect) - location: color-field-provider.svelte.ts:521-525 (
$effect(() => { const field = this.provider.field; if (!field) return; field.inputId.current = opts.id.current; })) - evidence: lead-confirmed by direct read — identical
$effectshape to date-field (932-936) and time-field (531-535); the reference NumberField uses a direct guard (number-field:585-587). - impact: no live loop (write-only + stable id), but contrary to A30 doctrine + the NumberField reference. See SYS-A30-EFFECT in SUMMARY.
- proposed-fix: replace with a direct constructor assignment matching NumberField; apply across date/time/color-field.
- verify: [lead-added] the color-field agent listed "Behavior" as a no-findings dimension, which masked the
$effectid-wiring; lead read of color-field:521-525 confirms it. Systemic MEDIUM. - fix-status: open
No-findings dimensions
Contract, Behavior (except A30 id-wiring — see color-field-A30), DOM-selector, TSC
Theming facts (E-bis)
- magic z-index: none
- magic literals: none
- undeclared parts: none
- roles clean: true · variants clean: true
- label-font (one step below input?): CLEAN: calc(1em - (var(--font-size-md) - var(--font-size-sm))) at src/uix/eidos/components/color-field/color-field.css:106 correctly implements label one typographic step below input size (md → sm = 2px)
Tests (F)
- exists: true · env: jsdom
- covers: segment-commit: RGB fill sequencing (lines 100-123); keyboard: hex segment digit input with aria spinbutton (125-155); format-select: switching formats + allowedFormats narrowing + locked state (157-188); hidden-input: form field name/value wiring + required attribute (190-257); label-focus: label click routes focus to first segment (252-253)
- untested: readonly-segment-without-value warning (A24 guard); backspace navigation edge case (moveToPrevSegment on null segment); Home/End key boundary behaviors (first-item / last-item); readonly segments interaction with keyboard input; Arrow key wrapping (cycle vs no-cycle per channel config)