You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
36 lines
3.6 KiB
36 lines
3.6 KiB
# Audit: editable
|
|
audit-version: 1
|
|
audited-at: 2026-06-26
|
|
scope: (SCOPE-DRIFT → SYS-1)
|
|
method: adversarially-verified workflow (analyze → refute); HIGH/CRITICAL lead-verified. Clean-check pseudo-findings dropped. B4 ground-truth: segmented date/time/color-field register inputId via $effect (SYS-A30-EFFECT, no loop); number-field is the direct-assignment reference.
|
|
provider: src/uix/soma/components/editable/editable-provider.svelte.ts
|
|
field-family (A13/A24-26/A30): Not a field-family component; does not participate in Field composition. Optional hidden-input for form submission is correctly declared and configured with name, value, required, disabled propagation.
|
|
|
|
## Summary
|
|
Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 1 · LOW 0.
|
|
|
|
## Findings
|
|
### MEDIUM: SYS-1 SCOPE-DRIFT — editable-001 <!-- id: editable-001 -->
|
|
- dimension: Morfo
|
|
- rule: SYS-1 SCOPE-DRIFT
|
|
- location: src/uix/morfo/components/editable.ts:7
|
|
- evidence: Morfo declares scope: ['soma', 'sema'] but eidos recipe directory exists at src/uix/eidos/components/editable/ with recipe tokens in src/uix/eidos/lib/recipes/base.ts:2724-2815
|
|
- impact: The morfo scope should include 'eidos' to signal that the component has visual styling rules. Missing 'eidos' in scope creates confusion about the component's boundaries.
|
|
- proposed-fix: Change morfo line 7 from scope: ['soma', 'sema'] to scope: ['soma', 'sema', 'eidos']
|
|
- verify: [confirmed] Confirmed. editable.ts:7 declares `scope: ['soma', 'sema']` — verified by reading the file. The eidos layer materially implements this component: 13 files under src/uix/eidos/components/editable/ (incl. editable.css) plus a recipe block at src/uix/eidos/lib/recipes/base.ts:2724 (`editable: {`). The Layer field is documented in types.ts:799 as 'Layers that implement this component', so omitting 'eidos' while shipping a full eidos implementation is genuine contract drift — matches the SYS-1 scope-drift baseline (MEDIUM). Severity MEDIUM is correct: this is a contract/documentation inconsistency, not a behavior bug (the eidos CSS still loads and works regardless of the morfo scope array). Confirmed systemic, not editable-specific: combobox, color-picker, date-field, calendar all have eidos CSS files yet their morfo scope is `['soma', 'sema']` too (e.g. calendar.ts:7, combobox.ts:7, color-picker.ts:7). Proposed fix (add 'eidos' to the array) is correct.
|
|
- fix-status: fixed (212624e0)
|
|
|
|
## No-findings dimensions
|
|
Contract (2-of-3 parts rule), Contract (morfo as const satisfies), Contract (data-/aria- naming), Contract (declared events fired), Behavior (A30 id registration), Behavior (A6 frame disposal), Behavior (A31 O(N^2)), Behavior (keyboard APG match), Behavior (two-moments commit ordering), DOM-selector (CSS.escape), Frontier (soma->eidos import), Theming (9-role limit), Theming (magic z-index), Theming (magic opacity), Theming (magic literals px/rem/em/%)
|
|
|
|
## Theming facts (E-bis)
|
|
- magic z-index: none
|
|
- magic literals: none
|
|
- undeclared parts: none
|
|
- roles clean: true · variants clean: true
|
|
|
|
## Tests (F)
|
|
- exists: true · env: jsdom
|
|
- covers: startEdit with focus and state projection; preview activation (click/dblclick/focus modes); keyboard commit/cancel (Enter/Escape keys); blur control guards (focus retention on trigger buttons); readonly and disabled state enforcement; trigger label exposure and disabled states; value commit and revert semantics
|
|
- untested: hidden-input form submission with name/required/disabled propagation; maxLength enforcement on input; autoResize field-sizing behavior; blur submit vs cancel mode differentiation; selectOnFocus text selection on edit start
|