3.5 KiB
Audit: pin-input
audit-version: 1 audited-at: 2026-06-26 scope: method: adversarially-verified workflow (analyze → refute); HIGH/CRITICAL lead-verified. Clean-check pseudo-findings dropped. B4 ground-truth: segmented date/time/color-field register inputId via $effect (SYS-A30-EFFECT, no loop); number-field is the direct-assignment reference. provider: src/uix/soma/components/pin-input/pin-input-provider.svelte.ts field-family (A13/A24-26/A30): A13-PASS: Hidden input rendered at line 92 of src/uix/soma/components/pin-input/components/pin-input.svelte with name attribute propagated from opts.name (line 366 of provider). A30-PASS: inputId registered via direct assignment in PinInputProvider constructor (line 124 of pin-input-provider.svelte.ts), NOT $effect, matching the Field.inputId convention. Test confirms at line 136 of pin-input-prov
Summary
Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 1 · LOW 0.
Findings
MEDIUM: THEMING §5: Recipe font-weight tokens MUST reference --font-weight-* variables, not litera — pin-input-001
- dimension: E-bis: Theming
- rule: THEMING §5: Recipe font-weight tokens MUST reference --font-weight-* variables, not literal numeric values
- location: src/uix/eidos/lib/recipes/base.ts:4190
- evidence: 'cell-font-weight': '500' should be 'var(--font-weight-medium)'
- impact: Decouples the pin-input cell font weight from the canonical type scale, breaking theming coherence if --font-weight-medium is ever changed
- proposed-fix: Change line 4190 from "'cell-font-weight': '500'," to "'cell-font-weight': 'var(--font-weight-medium)',"
- verify: [confirmed] Confirmed at src/uix/eidos/lib/recipes/base.ts:4190: the line is exactly "'cell-font-weight': '500'," — a numeric literal. The canonical token exists (generated/base.css:341: "--font-weight-medium: 500;"), so 500 maps 1:1 to --font-weight-medium and should consume the value-preserving token. This is genuine drift, not a physically-fixed value: a grep across the entire base.ts recipe file shows EVERY other font-weight declaration uses var(--font-weight-*) (e.g. lines 48, 153, 314, 1453-1457, 1669, 1686, 3670-3674, 4196 contexts), and a regex for numeric-literal font-weights ('font-weight':') matches ONLY line 4190 — it is the sole offender in the whole file. THEMING §5 / 'no magic literals — tokenize don't intentionalize' (feedback_no_intentional_magic_numbers): a literal that equals a scale step must reference the token. MEDIUM (token inconsistency / magic literal) and high confidence are both appropriate.
- fix-status: open
No-findings dimensions
A: Contract (morfo), B: Behavior (soma), C: DOM-selector, D: Frontier (soma/eidos boundary), E: TSC, F: Tests, G: Redundancy
Theming facts (E-bis)
- magic z-index: none
- magic literals: pin-input recipe line 4190: literal '500' for cell-font-weight
- undeclared parts: none
- roles clean: true · variants clean: true
- label-font (one step below input?): N/A (no visible label component in morfo; soma uses aria-label on hidden input)
Tests (F)
- exists: true · env: jsdom
- covers: onComplete callback firing once when value reaches length; pattern filtering on oninput; paste transformation and distribution; selection tracking and cell state derivation; focus/blur lifecycle; Field flag OR-merging (disabled, readonly, required, invalid)
- untested: IME/drop edge cases (note: keydown.preventDefault alone is insufficient per A26 — but this is not a segmented input so A26 does not apply)