Files
LEDMatrix/web_interface/static/v3/js/utils/dialog.js
ChuckandClaude Opus 5 d1e821c625 fix(web): harden, polish and optimize the web UI per the Sept 2026 audit (#568)
* fix(web): harden, polish and optimize the web UI per the September 2026 audit

Works through docs/archive/WEB_UI_AUDIT_2026-09.md (health 8/20).

Implementation integrity (P0)
- app.css now defines every utility class the templates and JS use,
  including .hidden, so the ~145 JS show/hide toggles work. Button reset,
  and base component rules (.btn, .form-control) wrapped in :where() so
  utility classes on the same element win. New static-audit test fails
  when a used utility class has no rule.

Accessibility
- Focus rings render (the old ring rule referenced undefined variables);
  one :focus-visible outline everywhere; skip link; labelled nav landmarks.
- Shared dialog helper (js/utils/dialog.js): role/aria-modal, focus trap,
  Escape, focus return, applied to every modal.
- Named icon-only buttons and labelled ~70 form fields.
- Toasts announced once; errors persist >= 10s; one showNotification.
- Captive WiFi page: live region, timeouts, dark mode, 16px inputs.

Performance (Pi Zero 2 W)
- SSE streams and tab timers pause when hidden or off-tab; the display
  stream only runs while a preview is visible. app-shell.js deferred.
- Widget scripts served as one versioned bundle (/assets/widgets.js):
  52 -> 21 script tags, 66 -> 35 requests on first load.
- Stdlib gzip fallback when flask-compress is missing: first-load JS/CSS
  1358 KB -> 291 KB on the wire. SSE untouched.

Theming and responsive
- File managers, form fields and Fonts upload on theme tokens; bare
  inputs themed in dark mode; no more white surfaces.
- No horizontal overflow at 375px on any tab; 44px touch targets on
  coarse pointers; reduced-motion respected; header title truncates.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(web): clear Codacy findings on #568

- json-file-manager: focus-trap releases kept in a Map (no dynamic
  property access or delete; no value-returning forEach callback)
- notification / schedule-picker: style and day-label lookups via Map
- app.js: move the pending-queue assignment out of the expression
- diff_viewer / error_handler: named function declarations instead of
  arrow consts

No behavior change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: check the OAuth widget ships in the widget bundle

base.html no longer tags widget scripts one by one; they load through
/assets/widgets.js. Assert the page requests the bundle and the bundle
contains google-oauth.js, which is what the test was protecting.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(web): address review feedback on #568

- widget bundle version fingerprints every file (name, mtime_ns, size)
- gzip fallback appends Accept-Encoding to an existing Vary header
- dialog helper: releasing a non-top dialog no longer moves focus out of
  the dialog the user is in
- labels: file-upload targets its file input; fallback config fields get
  label for/id pairs; native color input has a fallback name
- utility audit also reads class names inside bound :class expressions

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(web): give the native color-picker input an accessible name

CodeRabbit flagged this on PR #568 as an outside-diff finding (never
posted inline, so it was missed in the round of fixes that addressed
the other 6 review comments). The <input type="color"> only carried a
title attribute; screen readers don't reliably announce title, and
there's no other label naming the control when showHexInput is false.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(web): clear Codacy findings in app-shell.js

- drop the unused catch binding on the SSE JSON parse
- move the pending-notification queue assignment out of the expression

No behavior change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(web): contain plugin widgets/ dir and bound style-editor retries

From CodeRabbit review on #568 (code that arrived with the main merge):
- serve_plugin_widget resolves widgets/ with resolve_under before
  resolving the manifest script under it, so a symlinked widgets
  directory can't become the containment base (CWE-22). New test.
- style-editor init stops polling after ~10s when the widget never
  registers and leaves the plain fallback fields in place.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 09:42:24 -04:00

140 lines
5.0 KiB
JavaScript

/**
* Shared modal-dialog accessibility helper.
*
* The UI has several modal implementations (inline markup toggled with
* style.display, markup injected and removed, the `hidden` class). This helper
* deliberately does not show or hide anything — each caller keeps its own
* visibility logic — it only supplies what every modal was missing:
*
* - role="dialog", aria-modal="true" and aria-labelledby on the panel
* - initial focus inside the panel
* - Tab / Shift+Tab kept inside the panel while it is open
* - Escape routed to the caller's close function
* - focus returned to whatever was focused before the dialog opened
*
* Usage:
* const release = window.LEDDialog.trap(panelEl, {
* labelledBy: 'my-modal-title', // id of the visible heading (optional)
* label: 'Plugin files', // aria-label when there is no heading
* initialFocus: inputEl, // element or selector (optional)
* onEscape: closeMyModal // omit to ignore Escape
* });
* // ...when the modal closes (from any path):
* release();
*
* Nested dialogs stack: only the top-most trap handles Tab and Escape.
* release() is idempotent, and calling trap() again on the same panel
* releases the previous trap first.
*/
(function () {
'use strict';
const FOCUSABLE = [
'a[href]', 'area[href]', 'button:not([disabled])',
'input:not([disabled]):not([type="hidden"])', 'select:not([disabled])',
'textarea:not([disabled])', 'iframe', '[contenteditable="true"]',
'[tabindex]:not([tabindex="-1"])'
].join(',');
const stack = [];
function visible(el) {
return !!(el.offsetWidth || el.offsetHeight || el.getClientRects().length);
}
function focusables(panel) {
return Array.prototype.filter.call(panel.querySelectorAll(FOCUSABLE), visible);
}
function onKeydown(e) {
const top = stack[stack.length - 1];
if (!top) return;
if (e.key === 'Escape' && top.onEscape) {
e.preventDefault();
e.stopPropagation();
top.onEscape(e);
return;
}
if (e.key !== 'Tab') return;
const items = focusables(top.panel);
if (items.length === 0) {
e.preventDefault();
top.panel.focus();
return;
}
const first = items[0];
const last = items[items.length - 1];
const active = document.activeElement;
if (!top.panel.contains(active)) {
e.preventDefault();
first.focus();
} else if (e.shiftKey && active === first) {
e.preventDefault();
last.focus();
} else if (!e.shiftKey && active === last) {
e.preventDefault();
first.focus();
}
}
function trap(panel, opts) {
if (!panel) return function () {};
opts = opts || {};
const existing = stack.find(function (t) { return t.panel === panel; });
if (existing) existing.release();
panel.setAttribute('role', opts.role || 'dialog');
panel.setAttribute('aria-modal', 'true');
if (opts.labelledBy) {
panel.setAttribute('aria-labelledby', opts.labelledBy);
} else if (opts.label) {
panel.setAttribute('aria-label', opts.label);
}
if (!panel.hasAttribute('tabindex')) panel.setAttribute('tabindex', '-1');
const entry = {
panel: panel,
onEscape: opts.onEscape || null,
returnTo: document.activeElement,
released: false,
release: null
};
entry.release = function () {
if (entry.released) return;
entry.released = true;
const wasTop = stack[stack.length - 1] === entry;
const i = stack.indexOf(entry);
if (i !== -1) stack.splice(i, 1);
if (stack.length === 0) document.removeEventListener('keydown', onKeydown, true);
// Releasing a dialog underneath another one must not pull focus
// out of the dialog the user is actually in.
if (!wasTop) return;
const target = entry.returnTo;
const active = stack[stack.length - 1];
if (active && !(target && active.panel.contains(target))) {
active.panel.focus();
} else if (target && typeof target.focus === 'function' && document.contains(target)) {
target.focus();
}
};
stack.push(entry);
if (stack.length === 1) document.addEventListener('keydown', onKeydown, true);
// Focus after the caller has made the panel visible.
requestAnimationFrame(function () {
if (entry.released) return;
let target = opts.initialFocus;
if (typeof target === 'string') target = panel.querySelector(target);
if (!target || !visible(target)) target = focusables(panel)[0] || panel;
target.focus();
});
return entry.release;
}
window.LEDDialog = { trap: trap };
})();