Files
LEDMatrix/web_interface/static/v3/js/widgets/text-input.js
T
ChuckandClaude Opus 5 d1e821c625 fix(web): harden, polish and optimize the web UI per the Sept 2026 audit (#568)
* fix(web): harden, polish and optimize the web UI per the September 2026 audit

Works through docs/archive/WEB_UI_AUDIT_2026-09.md (health 8/20).

Implementation integrity (P0)
- app.css now defines every utility class the templates and JS use,
  including .hidden, so the ~145 JS show/hide toggles work. Button reset,
  and base component rules (.btn, .form-control) wrapped in :where() so
  utility classes on the same element win. New static-audit test fails
  when a used utility class has no rule.

Accessibility
- Focus rings render (the old ring rule referenced undefined variables);
  one :focus-visible outline everywhere; skip link; labelled nav landmarks.
- Shared dialog helper (js/utils/dialog.js): role/aria-modal, focus trap,
  Escape, focus return, applied to every modal.
- Named icon-only buttons and labelled ~70 form fields.
- Toasts announced once; errors persist >= 10s; one showNotification.
- Captive WiFi page: live region, timeouts, dark mode, 16px inputs.

Performance (Pi Zero 2 W)
- SSE streams and tab timers pause when hidden or off-tab; the display
  stream only runs while a preview is visible. app-shell.js deferred.
- Widget scripts served as one versioned bundle (/assets/widgets.js):
  52 -> 21 script tags, 66 -> 35 requests on first load.
- Stdlib gzip fallback when flask-compress is missing: first-load JS/CSS
  1358 KB -> 291 KB on the wire. SSE untouched.

Theming and responsive
- File managers, form fields and Fonts upload on theme tokens; bare
  inputs themed in dark mode; no more white surfaces.
- No horizontal overflow at 375px on any tab; 44px touch targets on
  coarse pointers; reduced-motion respected; header title truncates.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(web): clear Codacy findings on #568

- json-file-manager: focus-trap releases kept in a Map (no dynamic
  property access or delete; no value-returning forEach callback)
- notification / schedule-picker: style and day-label lookups via Map
- app.js: move the pending-queue assignment out of the expression
- diff_viewer / error_handler: named function declarations instead of
  arrow consts

No behavior change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test: check the OAuth widget ships in the widget bundle

base.html no longer tags widget scripts one by one; they load through
/assets/widgets.js. Assert the page requests the bundle and the bundle
contains google-oauth.js, which is what the test was protecting.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(web): address review feedback on #568

- widget bundle version fingerprints every file (name, mtime_ns, size)
- gzip fallback appends Accept-Encoding to an existing Vary header
- dialog helper: releasing a non-top dialog no longer moves focus out of
  the dialog the user is in
- labels: file-upload targets its file input; fallback config fields get
  label for/id pairs; native color input has a fallback name
- utility audit also reads class names inside bound :class expressions

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(web): give the native color-picker input an accessible name

CodeRabbit flagged this on PR #568 as an outside-diff finding (never
posted inline, so it was missed in the round of fixes that addressed
the other 6 review comments). The <input type="color"> only carried a
title attribute; screen readers don't reliably announce title, and
there's no other label naming the control when showHexInput is false.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(web): clear Codacy findings in app-shell.js

- drop the unused catch binding on the SSE JSON parse
- move the pending-notification queue assignment out of the expression

No behavior change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(web): contain plugin widgets/ dir and bound style-editor retries

From CodeRabbit review on #568 (code that arrived with the main merge):
- serve_plugin_widget resolves widgets/ with resolve_under before
  resolving the manifest script under it, so a symlinked widgets
  directory can't become the containment base (CWE-22). New test.
- style-editor init stops polling after ~10s when the widget never
  registers and leaves the plain fallback fields in place.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 09:42:24 -04:00

245 lines
9.7 KiB
JavaScript

/**
* LEDMatrix Text Input Widget
*
* Enhanced text input with validation, placeholder, and pattern support.
*
* Schema example:
* {
* "username": {
* "type": "string",
* "x-widget": "text-input",
* "x-options": {
* "placeholder": "Enter username",
* "pattern": "^[a-zA-Z0-9_]+$",
* "patternMessage": "Only letters, numbers, and underscores allowed",
* "minLength": 3,
* "maxLength": 20,
* "prefix": "@",
* "suffix": null,
* "clearable": true
* }
* }
* }
*
* @module TextInputWidget
*/
(function() {
'use strict';
const base = window.BaseWidget ? new window.BaseWidget('TextInput', '1.0.0') : null;
function escapeHtml(text) {
if (base) return base.escapeHtml(text);
const div = document.createElement('div');
div.textContent = String(text);
return div.innerHTML.replace(/"/g, '&quot;').replace(/'/g, '&#39;');
}
function sanitizeId(id) {
if (base) return base.sanitizeId(id);
return String(id).replace(/[^a-zA-Z0-9_-]/g, '_');
}
function triggerChange(fieldId, value) {
if (base) {
base.triggerChange(fieldId, value);
} else {
const event = new CustomEvent('widget-change', {
detail: { fieldId, value },
bubbles: true,
cancelable: true
});
document.dispatchEvent(event);
}
}
window.LEDMatrixWidgets.register('text-input', {
name: 'Text Input Widget',
version: '1.0.0',
render: function(container, config, value, options) {
const fieldId = sanitizeId(options.fieldId || container.id || 'text_input');
const xOptions = config['x-options'] || config['x_options'] || {};
const placeholder = xOptions.placeholder || '';
const pattern = xOptions.pattern || '';
const patternMessage = xOptions.patternMessage || 'Invalid format';
// Sanitize minLength/maxLength - must be finite non-negative integers
const rawMinLength = parseInt(xOptions.minLength, 10);
const rawMaxLength = parseInt(xOptions.maxLength, 10);
let minLength = (Number.isFinite(rawMinLength) && rawMinLength >= 0 && rawMinLength <= 10000000)
? rawMinLength : null;
let maxLength = (Number.isFinite(rawMaxLength) && rawMaxLength >= 0 && rawMaxLength <= 10000000)
? rawMaxLength : null;
// Normalize constraints: ensure maxLength >= minLength when both are set
if (minLength !== null && maxLength !== null && maxLength < minLength) {
maxLength = minLength;
}
const prefix = xOptions.prefix || '';
const suffix = xOptions.suffix || '';
const clearable = xOptions.clearable === true;
const disabled = xOptions.disabled === true;
const currentValue = value !== null && value !== undefined ? String(value) : '';
let html = `<div id="${fieldId}_widget" class="text-input-widget" data-field-id="${fieldId}" data-pattern-message="${escapeHtml(patternMessage)}">`;
// Container for prefix/input/suffix layout
const hasAddons = prefix || suffix || clearable;
if (hasAddons) {
html += '<div class="flex items-center">';
if (prefix) {
html += `<span class="inline-flex items-center px-3 text-sm text-gray-500 bg-gray-100 border border-r-0 border-gray-300 rounded-l-md">${escapeHtml(prefix)}</span>`;
}
}
const roundedClass = hasAddons
? (prefix && suffix ? '' : (prefix ? 'rounded-r-md' : 'rounded-l-md'))
: 'rounded-md';
html += `
<input type="text"
id="${fieldId}_input"
name="${escapeHtml(options.name || fieldId)}"
value="${escapeHtml(currentValue)}"
placeholder="${escapeHtml(placeholder)}"
${pattern ? `pattern="${escapeHtml(pattern)}"` : ''}
${minLength !== null ? `minlength="${minLength}"` : ''}
${maxLength !== null ? `maxlength="${maxLength}"` : ''}
${disabled ? 'disabled' : ''}
onchange="window.LEDMatrixWidgets.getHandlers('text-input').onChange('${fieldId}')"
oninput="window.LEDMatrixWidgets.getHandlers('text-input').onInput('${fieldId}')"
class="form-input flex-1 ${roundedClass} border-gray-300 shadow-sm focus:border-blue-500 focus:ring-blue-500 ${disabled ? 'bg-gray-100 cursor-not-allowed' : 'bg-white'} text-black placeholder:text-gray-400">
`;
if (clearable && !disabled) {
html += `
<button type="button"
id="${fieldId}_clear"
onclick="window.LEDMatrixWidgets.getHandlers('text-input').onClear('${fieldId}')"
class="inline-flex items-center px-2 text-gray-400 hover:text-gray-600 ${currentValue ? '' : 'hidden'}"
title="Clear" aria-label="Clear">
<i class="fas fa-times" aria-hidden="true"></i>
</button>
`;
}
if (suffix) {
html += `<span class="inline-flex items-center px-3 text-sm text-gray-500 bg-gray-100 border border-l-0 border-gray-300 rounded-r-md">${escapeHtml(suffix)}</span>`;
}
if (hasAddons) {
html += '</div>';
}
// Validation message area
html += `<div id="${fieldId}_error" class="text-sm text-red-600 mt-1 hidden"></div>`;
// Character count if maxLength specified
if (maxLength !== null) {
html += `<div id="${fieldId}_count" class="text-xs text-gray-400 mt-1 text-right">${currentValue.length}/${maxLength}</div>`;
}
html += '</div>';
container.innerHTML = html;
},
getValue: function(fieldId) {
const safeId = sanitizeId(fieldId);
const input = document.getElementById(`${safeId}_input`);
return input ? input.value : '';
},
setValue: function(fieldId, value) {
const safeId = sanitizeId(fieldId);
const input = document.getElementById(`${safeId}_input`);
if (input) {
input.value = value !== null && value !== undefined ? String(value) : '';
this.handlers.onInput(fieldId);
}
},
validate: function(fieldId) {
const safeId = sanitizeId(fieldId);
const input = document.getElementById(`${safeId}_input`);
const errorEl = document.getElementById(`${safeId}_error`);
const widget = document.getElementById(`${safeId}_widget`);
if (!input) return { valid: true, errors: [] };
// Clear any prior custom validity to avoid stale errors
input.setCustomValidity('');
let isValid = input.checkValidity();
let errorMessage = input.validationMessage;
// Use custom pattern message if pattern mismatch
if (!isValid && input.validity.patternMismatch && widget) {
const patternMessage = widget.dataset.patternMessage;
if (patternMessage) {
errorMessage = patternMessage;
input.setCustomValidity(patternMessage);
// Re-check validity with custom message set
isValid = input.checkValidity();
}
}
if (errorEl) {
if (!isValid) {
errorEl.textContent = errorMessage;
errorEl.classList.remove('hidden');
input.classList.add('border-red-500');
} else {
errorEl.classList.add('hidden');
input.classList.remove('border-red-500');
}
}
return { valid: isValid, errors: isValid ? [] : [errorMessage] };
},
handlers: {
onChange: function(fieldId) {
const widget = window.LEDMatrixWidgets.get('text-input');
widget.validate(fieldId);
triggerChange(fieldId, widget.getValue(fieldId));
},
onInput: function(fieldId) {
const safeId = sanitizeId(fieldId);
const input = document.getElementById(`${safeId}_input`);
const clearBtn = document.getElementById(`${safeId}_clear`);
const countEl = document.getElementById(`${safeId}_count`);
// Clear any stale custom validity to allow form submission after user fixes input
if (input && input.validity.customError) {
input.setCustomValidity('');
}
if (clearBtn) {
clearBtn.classList.toggle('hidden', !input.value);
}
if (countEl && input) {
const maxLength = input.maxLength;
if (maxLength > 0) {
countEl.textContent = `${input.value.length}/${maxLength}`;
}
}
},
onClear: function(fieldId) {
const widget = window.LEDMatrixWidgets.get('text-input');
widget.setValue(fieldId, '');
triggerChange(fieldId, '');
}
}
});
console.log('[TextInputWidget] Text input widget registered');
})();