You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
36 lines
3.3 KiB
36 lines
3.3 KiB
# Audit: image-picker
|
|
audit-version: 1
|
|
audited-at: 2026-06-26
|
|
scope: (SCOPE-DRIFT → SYS-1)
|
|
method: adversarially-verified workflow; HIGH lead-verified. B7 ground-truth: Toolbar A35 + Form A36 incidents STAYED FIXED (untrack present); toast/clipboard/drag-drop use uix.timers (no A6 leak); button is clean (its archetype finding was inert — Spinner not runtime-registered); data-size/data-shape are eidos visual attrs (not contract violations).
|
|
provider: /g/dev/svelte/vicen/src/uix/soma/components/image-picker/image-picker-provider.svelte.ts
|
|
cleanup-audit (A6/A35/A36): One $effect at line 82: reads opts.file.current, creates URL.createObjectURL, writes to this.url, cleanup function properly returns and calls URL.revokeObjectURL(u). Cleanup is attached and will fire on effect cleanup. No timers, listeners, ResizeObserver, IntersectionObserver, MutationObserver, or
|
|
|
|
## Summary
|
|
Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 1 · LOW 0.
|
|
|
|
## Findings
|
|
### MEDIUM: SYS-1 scope-drift: a component with a real eidos implementation (recipe dir + CSS selectin — image-picker-NEW-001 <!-- id: image-picker-NEW-001 -->
|
|
- dimension: A_Contract
|
|
- rule: SYS-1 scope-drift: a component with a real eidos implementation (recipe dir + CSS selecting morfo data-attrs) MUST list 'eidos' in morfo.scope ('Layers that implement this component' — types.ts:798-799).
|
|
- location: src/uix/morfo/components/image-picker.ts:20
|
|
- evidence: Morfo declares `scope: ['soma', 'sema']` (line 20), omitting 'eidos'. But a full eidos layer implements the component: src/uix/eidos/components/image-picker/{image-picker.svelte,image-picker.css,types.ts,index.ts} all exist, and image-picker.css selects exclusively against morfo-emitted data-attrs — `[data-image-picker]` (:12), `[data-image-picker][data-disabled]` (:18), `[data-image-picker-preview][data-rotation='90']` (:49), `[data-image-picker-toolbar]` (:59), `[data-image-picker-rotate]`/`[data-image-picker-remove]` (:67-68). These are the morfo's `contracts.cssSelectors` surface, so eidos is a genuine implementing layer per the scope doctrine.
|
|
- impact: Contract drift: the morfo under-declares its implementing layers. Tooling/coverage that keys off `scope` (lint, layer audits, sema coverage) treats the component as having no eidos layer, masking the eidos↔morfo contract. Cosmetic-to-tooling, no runtime user impact — matches the confirmed SYS-1 baseline severity (MEDIUM).
|
|
- proposed-fix: Add 'eidos' to the scope array: `scope: ['soma', 'sema', 'eidos']` in src/uix/morfo/components/image-picker.ts:20.
|
|
- verify: [verifier-added] added by adversarial verify pass
|
|
- fix-status: fixed (212624e0)
|
|
|
|
## No-findings dimensions
|
|
B_Behavior_A6, B_Behavior_A35, B_Behavior_A36, A_Contract_Parts, A_Contract_DataAria_SyncAttrs, D_Frontier_SomaEidos, D_Frontier_DoubleWrite, E_Theming_MagicZ, E_Theming_MagicColors, E_Theming_MagicOpacity, E_bis_RecipeFocus, E_bis_RecipeButton, F_Tests, G_Redundancy
|
|
|
|
## Theming facts (E-bis)
|
|
- magic z-index: none
|
|
- magic literals: none
|
|
- undeclared parts: none
|
|
- roles clean: true · variants clean: true
|
|
|
|
## Tests (F)
|
|
- exists: true · env: jsdom
|
|
- covers: state_empty_ready; setFile_fires_onSelect_onChange_triggers_commit_select; rotate_cycles_90_wraps_360; remove_clears_file_resets_transforms; filter_composition; disabled_blocks_actions
|
|
- untested:
|