Skip to content

finding(examples): seven catalog badge nodes author their text under children, which ui:badge never reads — three demos draw nothing at all #6829

Description

@claude

Found while implementing #6805 + #6806 (the scroll-area/badgecontent pair), by censusing
every badge node in the catalog to size that PR's corpus sweep. Out of that PR's fence — it
names the two badge nodes authoring content in sidebar-with-badges — so it is filed
rather than fixed.

Same defect class as #6773 / #6788 / #6805 / #6806, a different phantom key. Those four are
all content. This one is children, and that difference is why none of the existing
instruments see it.

Measured

packages/components/src/renderers/data-display/badge.tsx:32 renders
schema.label || renderChildren(schema.body). It reads label and body. It does
not read children — unlike card.tsx, which reads children || body.

Seven catalog badge nodes author children anyway. Census over all 431 fixtures, on
origin/main26896c689:

badge nodes 40 in 12 categories
keys authored on them: type 40 · variant 36 · label 31 · className 8 ·
children 7 · content 2

The content 2 are #6806, repaired in PR for #6805/#6806. The children 7 are this card:

components-basic-span/default-badge children: [ text ]
components-basic-span/secondary-badge children: [ text ]
components-basic-span/status-badges .children[0..2] children: [ text ] (3 nodes)
core-schema-renderer/nested-schema-example ...children[0..1] children: "Nested" /
children: "Components"

Rendered through the real SchemaRenderer the way the docs gallery renders them:

entry elements text
components-basic-span/default-badge 2 ""
components-basic-span/secondary-badge 2 ""
components-basic-span/status-badges 5 ""
core-schema-renderer/nested-schema-example 13 "Parent ComponentSibling Component
All rendered from a single schema tree"

Three of those entries draw literally nothing — the whole demo is one empty pill. The
fourth renders its surrounding prose and silently drops both badges (Nested and
Components are absent from its text).

components-basic-span is a badge category: three of its entries are empty boxes on the
published page.

⭐ Why every existing instrument is blind to this one

This is the part worth keeping. The content members of this class are caught, in principle,
by two different signals. This variant emits neither.

  1. No DOM leak. The content members leak the authored string to the host element as
    content="..." — the finding: the DOM-leak sweep never reaches packages/components/src/renderers/** — four layout/basic renderers still carry the unfixed spread #5574 signature, and what made finding(docs,examples): all five aspect-ratio docs demos author content, a key the renderer never reads — every demo on the published page renders an empty ratio box #6773/finding(examples): the basic-context-menu demo authors its trigger card under content, which ui:card never reads — the tile is an empty dashed box #6788/finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805/finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 findable by
    attribute sweep. Measured here: leaked[content] = 0 on all four entries. children is a
    pipeline key the renderer machinery consumes, so it never reaches the DOM. A leak sweep
    cannot find this.

  2. catalog-gallery-render.test.tsx passes — via a THIRD escape route. Its non-vacuity
    control is elements > WRAPPER_ELEMENTS || text, with WRAPPER_ELEMENTS = 2. Measured in
    that file's own harness:

    components-basic-span/default-badge elements=3 text="" drewSomething=true
    components-basic-span/secondary-badge elements=3 text="" drewSomething=true
    components-basic-span/status-badges elements=6 text="" drewSomething=true
    

    The empty badge's own host element is the third element, so a demo that draws nothing
    but an empty pill clears the control on the pill. That is distinct from the two escapes
    already recorded on finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805 (Radix's injected scrollbar stylesheet counting as text) and
    finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 (a large correct render hiding a small omission). ⇒ three different holes in the
    same control
    , which strengthens the [Decision] What instrument stops the container-declaration class regenerating — and do the remaining 45 get fixed before it lands? #6779-style argument that the instrument belongs
    per-renderer rather than in a stricter global threshold.

  3. Neither zod nor tsc: BaseSchema is .passthrough() and carries [key: string]: any, and
    children is declared on BaseSchema — so this is worse than the content case, where
    at least a declared-key check would bite. children is declared and unread, which is
    exactly the shape PR docs(context-menu): author the trigger card's text under the key ui:card reads #6807's "READ set is strictly stronger than the DECLARED set" note
    calls out, with variant as its example.

⛔ Why this is filed, not fixed — the repair key is a genuine decision

The content members had one mechanical answer. This one has two, and they differ in kind:

⇒ this needs a ruling, not a sweep. Related to #6810 (the open needs-user-decision card
asking whether this class gets a global instrument): this is the fifth rediscovery, the
first one under a different key, and the first that the leak signature cannot find.

Related

#6810 (the decision card for this class) · #6805 · #6806 · #6788 · #6773 · #6771 (retiring
body) · #5574 (the DOM-leak class the content members belong to and this one does not)

Generated by Claude Code


Generated by Claude Code

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
       blocks
      (function() {
      function addCopyButtons() {
      document.querySelectorAll('pre code').forEach(function(codeBlock) {
      if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
      codeBlock.parentElement.setAttribute('data-copy-added', 'true');
      var btn = document.createElement('button');
      btn.textContent = 'Copy';
      btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
      btn.onmouseover = function() { this.style.opacity = '1'; };
      btn.onmouseout = function() { this.style.opacity = '0.7'; };
      btn.onclick = function() {
      navigator.clipboard.writeText(codeBlock.textContent).then(function() {
      btn.textContent = 'Copied!';
      setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
      });
      };
      codeBlock.parentElement.style.position = 'relative';
      codeBlock.parentElement.appendChild(btn);
      });
      }
      addCopyButtons();
      // Re-run on dynamic content
      var observer = new MutationObserver(addCopyButtons);
      observer.observe(document.body, { childList: true, subtree: true });
      })();
      }
      } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
      })();
      (function(){
      try {
      var __m = "github.com";
      var __re = new RegExp('^' + "github\\.com" + '
      finding(examples): seven catalog `badge` nodes author their text under `children`, which ui:badge never reads — three demos draw nothing at all · Issue #6829 · objectstack-ai/objectui · GitHub
      Skip to content

      finding(examples): seven catalog badge nodes author their text under children, which ui:badge never reads — three demos draw nothing at all #6829

      Description

      @claude

      Found while implementing #6805 + #6806 (the scroll-area/badgecontent pair), by censusing
      every badge node in the catalog to size that PR's corpus sweep. Out of that PR's fence — it
      names the two badge nodes authoring content in sidebar-with-badges — so it is filed
      rather than fixed.

      Same defect class as #6773 / #6788 / #6805 / #6806, a different phantom key. Those four are
      all content. This one is children, and that difference is why none of the existing
      instruments see it.

      Measured

      packages/components/src/renderers/data-display/badge.tsx:32 renders
      schema.label || renderChildren(schema.body). It reads label and body. It does
      not read children — unlike card.tsx, which reads children || body.

      Seven catalog badge nodes author children anyway. Census over all 431 fixtures, on
      origin/main26896c689:

      badge nodes 40 in 12 categories
      keys authored on them: type 40 · variant 36 · label 31 · className 8 ·
      children 7 · content 2
      

      The content 2 are #6806, repaired in PR for #6805/#6806. The children 7 are this card:

      components-basic-span/default-badge children: [ text ]
      components-basic-span/secondary-badge children: [ text ]
      components-basic-span/status-badges .children[0..2] children: [ text ] (3 nodes)
      core-schema-renderer/nested-schema-example ...children[0..1] children: "Nested" /
      children: "Components"
      

      Rendered through the real SchemaRenderer the way the docs gallery renders them:

      entry elements text
      components-basic-span/default-badge 2 ""
      components-basic-span/secondary-badge 2 ""
      components-basic-span/status-badges 5 ""
      core-schema-renderer/nested-schema-example 13 "Parent ComponentSibling Component
      All rendered from a single schema tree"
      

      Three of those entries draw literally nothing — the whole demo is one empty pill. The
      fourth renders its surrounding prose and silently drops both badges (Nested and
      Components are absent from its text).

      components-basic-span is a badge category: three of its entries are empty boxes on the
      published page.

      ⭐ Why every existing instrument is blind to this one

      This is the part worth keeping. The content members of this class are caught, in principle,
      by two different signals. This variant emits neither.

      1. No DOM leak. The content members leak the authored string to the host element as
        content="..." — the finding: the DOM-leak sweep never reaches packages/components/src/renderers/** — four layout/basic renderers still carry the unfixed spread #5574 signature, and what made finding(docs,examples): all five aspect-ratio docs demos author content, a key the renderer never reads — every demo on the published page renders an empty ratio box #6773/finding(examples): the basic-context-menu demo authors its trigger card under content, which ui:card never reads — the tile is an empty dashed box #6788/finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805/finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 findable by
        attribute sweep. Measured here: leaked[content] = 0 on all four entries. children is a
        pipeline key the renderer machinery consumes, so it never reaches the DOM. A leak sweep
        cannot find this.

      2. catalog-gallery-render.test.tsx passes — via a THIRD escape route. Its non-vacuity
        control is elements > WRAPPER_ELEMENTS || text, with WRAPPER_ELEMENTS = 2. Measured in
        that file's own harness:

        components-basic-span/default-badge elements=3 text="" drewSomething=true
        components-basic-span/secondary-badge elements=3 text="" drewSomething=true
        components-basic-span/status-badges elements=6 text="" drewSomething=true
        

        The empty badge's own host element is the third element, so a demo that draws nothing
        but an empty pill clears the control on the pill. That is distinct from the two escapes
        already recorded on finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805 (Radix's injected scrollbar stylesheet counting as text) and
        finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 (a large correct render hiding a small omission). ⇒ three different holes in the
        same control
        , which strengthens the [Decision] What instrument stops the container-declaration class regenerating — and do the remaining 45 get fixed before it lands? #6779-style argument that the instrument belongs
        per-renderer rather than in a stricter global threshold.

      3. Neither zod nor tsc: BaseSchema is .passthrough() and carries [key: string]: any, and
        children is declared on BaseSchema — so this is worse than the content case, where
        at least a declared-key check would bite. children is declared and unread, which is
        exactly the shape PR docs(context-menu): author the trigger card's text under the key ui:card reads #6807's "READ set is strictly stronger than the DECLARED set" note
        calls out, with variant as its example.

      ⛔ Why this is filed, not fixed — the repair key is a genuine decision

      The content members had one mechanical answer. This one has two, and they differ in kind:

      ⇒ this needs a ruling, not a sweep. Related to #6810 (the open needs-user-decision card
      asking whether this class gets a global instrument): this is the fifth rediscovery, the
      first one under a different key, and the first that the leak signature cannot find.

      Related

      #6810 (the decision card for this class) · #6805 · #6806 · #6788 · #6773 · #6771 (retiring
      body) · #5574 (the DOM-leak class the content members belong to and this one does not)

      Generated by Claude Code


      Generated by Claude Code

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        No labels
        No labels

        Type

        No type

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' finding(examples): seven catalog `badge` nodes author their text under `children`, which ui:badge never reads — three demos draw nothing at all · Issue #6829 · objectstack-ai/objectui · GitHub
          Skip to content

          finding(examples): seven catalog badge nodes author their text under children, which ui:badge never reads — three demos draw nothing at all #6829

          Description

          @claude

          Found while implementing #6805 + #6806 (the scroll-area/badgecontent pair), by censusing
          every badge node in the catalog to size that PR's corpus sweep. Out of that PR's fence — it
          names the two badge nodes authoring content in sidebar-with-badges — so it is filed
          rather than fixed.

          Same defect class as #6773 / #6788 / #6805 / #6806, a different phantom key. Those four are
          all content. This one is children, and that difference is why none of the existing
          instruments see it.

          Measured

          packages/components/src/renderers/data-display/badge.tsx:32 renders
          schema.label || renderChildren(schema.body). It reads label and body. It does
          not read children — unlike card.tsx, which reads children || body.

          Seven catalog badge nodes author children anyway. Census over all 431 fixtures, on
          origin/main26896c689:

          badge nodes 40 in 12 categories
          keys authored on them: type 40 · variant 36 · label 31 · className 8 ·
          children 7 · content 2
          

          The content 2 are #6806, repaired in PR for #6805/#6806. The children 7 are this card:

          components-basic-span/default-badge children: [ text ]
          components-basic-span/secondary-badge children: [ text ]
          components-basic-span/status-badges .children[0..2] children: [ text ] (3 nodes)
          core-schema-renderer/nested-schema-example ...children[0..1] children: "Nested" /
          children: "Components"
          

          Rendered through the real SchemaRenderer the way the docs gallery renders them:

          entry elements text
          components-basic-span/default-badge 2 ""
          components-basic-span/secondary-badge 2 ""
          components-basic-span/status-badges 5 ""
          core-schema-renderer/nested-schema-example 13 "Parent ComponentSibling Component
          All rendered from a single schema tree"
          

          Three of those entries draw literally nothing — the whole demo is one empty pill. The
          fourth renders its surrounding prose and silently drops both badges (Nested and
          Components are absent from its text).

          components-basic-span is a badge category: three of its entries are empty boxes on the
          published page.

          ⭐ Why every existing instrument is blind to this one

          This is the part worth keeping. The content members of this class are caught, in principle,
          by two different signals. This variant emits neither.

          1. No DOM leak. The content members leak the authored string to the host element as
            content="..." — the finding: the DOM-leak sweep never reaches packages/components/src/renderers/** — four layout/basic renderers still carry the unfixed spread #5574 signature, and what made finding(docs,examples): all five aspect-ratio docs demos author content, a key the renderer never reads — every demo on the published page renders an empty ratio box #6773/finding(examples): the basic-context-menu demo authors its trigger card under content, which ui:card never reads — the tile is an empty dashed box #6788/finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805/finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 findable by
            attribute sweep. Measured here: leaked[content] = 0 on all four entries. children is a
            pipeline key the renderer machinery consumes, so it never reaches the DOM. A leak sweep
            cannot find this.

          2. catalog-gallery-render.test.tsx passes — via a THIRD escape route. Its non-vacuity
            control is elements > WRAPPER_ELEMENTS || text, with WRAPPER_ELEMENTS = 2. Measured in
            that file's own harness:

            components-basic-span/default-badge elements=3 text="" drewSomething=true
            components-basic-span/secondary-badge elements=3 text="" drewSomething=true
            components-basic-span/status-badges elements=6 text="" drewSomething=true
            

            The empty badge's own host element is the third element, so a demo that draws nothing
            but an empty pill clears the control on the pill. That is distinct from the two escapes
            already recorded on finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805 (Radix's injected scrollbar stylesheet counting as text) and
            finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 (a large correct render hiding a small omission). ⇒ three different holes in the
            same control
            , which strengthens the [Decision] What instrument stops the container-declaration class regenerating — and do the remaining 45 get fixed before it lands? #6779-style argument that the instrument belongs
            per-renderer rather than in a stricter global threshold.

          3. Neither zod nor tsc: BaseSchema is .passthrough() and carries [key: string]: any, and
            children is declared on BaseSchema — so this is worse than the content case, where
            at least a declared-key check would bite. children is declared and unread, which is
            exactly the shape PR docs(context-menu): author the trigger card's text under the key ui:card reads #6807's "READ set is strictly stronger than the DECLARED set" note
            calls out, with variant as its example.

          ⛔ Why this is filed, not fixed — the repair key is a genuine decision

          The content members had one mechanical answer. This one has two, and they differ in kind:

          ⇒ this needs a ruling, not a sweep. Related to #6810 (the open needs-user-decision card
          asking whether this class gets a global instrument): this is the fifth rediscovery, the
          first one under a different key, and the first that the leak signature cannot find.

          Related

          #6810 (the decision card for this class) · #6805 · #6806 · #6788 · #6773 · #6771 (retiring
          body) · #5574 (the DOM-leak class the content members belong to and this one does not)

          Generated by Claude Code


          Generated by Claude Code

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            No labels
            No labels

            Type

            No type

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' finding(examples): seven catalog `badge` nodes author their text under `children`, which ui:badge never reads — three demos draw nothing at all · Issue #6829 · objectstack-ai/objectui · GitHub
              Skip to content

              finding(examples): seven catalog badge nodes author their text under children, which ui:badge never reads — three demos draw nothing at all #6829

              Description

              @claude

              Found while implementing #6805 + #6806 (the scroll-area/badgecontent pair), by censusing
              every badge node in the catalog to size that PR's corpus sweep. Out of that PR's fence — it
              names the two badge nodes authoring content in sidebar-with-badges — so it is filed
              rather than fixed.

              Same defect class as #6773 / #6788 / #6805 / #6806, a different phantom key. Those four are
              all content. This one is children, and that difference is why none of the existing
              instruments see it.

              Measured

              packages/components/src/renderers/data-display/badge.tsx:32 renders
              schema.label || renderChildren(schema.body). It reads label and body. It does
              not read children — unlike card.tsx, which reads children || body.

              Seven catalog badge nodes author children anyway. Census over all 431 fixtures, on
              origin/main26896c689:

              badge nodes 40 in 12 categories
              keys authored on them: type 40 · variant 36 · label 31 · className 8 ·
              children 7 · content 2
              

              The content 2 are #6806, repaired in PR for #6805/#6806. The children 7 are this card:

              components-basic-span/default-badge children: [ text ]
              components-basic-span/secondary-badge children: [ text ]
              components-basic-span/status-badges .children[0..2] children: [ text ] (3 nodes)
              core-schema-renderer/nested-schema-example ...children[0..1] children: "Nested" /
              children: "Components"
              

              Rendered through the real SchemaRenderer the way the docs gallery renders them:

              entry elements text
              components-basic-span/default-badge 2 ""
              components-basic-span/secondary-badge 2 ""
              components-basic-span/status-badges 5 ""
              core-schema-renderer/nested-schema-example 13 "Parent ComponentSibling Component
              All rendered from a single schema tree"
              

              Three of those entries draw literally nothing — the whole demo is one empty pill. The
              fourth renders its surrounding prose and silently drops both badges (Nested and
              Components are absent from its text).

              components-basic-span is a badge category: three of its entries are empty boxes on the
              published page.

              ⭐ Why every existing instrument is blind to this one

              This is the part worth keeping. The content members of this class are caught, in principle,
              by two different signals. This variant emits neither.

              1. No DOM leak. The content members leak the authored string to the host element as
                content="..." — the finding: the DOM-leak sweep never reaches packages/components/src/renderers/** — four layout/basic renderers still carry the unfixed spread #5574 signature, and what made finding(docs,examples): all five aspect-ratio docs demos author content, a key the renderer never reads — every demo on the published page renders an empty ratio box #6773/finding(examples): the basic-context-menu demo authors its trigger card under content, which ui:card never reads — the tile is an empty dashed box #6788/finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805/finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 findable by
                attribute sweep. Measured here: leaked[content] = 0 on all four entries. children is a
                pipeline key the renderer machinery consumes, so it never reaches the DOM. A leak sweep
                cannot find this.

              2. catalog-gallery-render.test.tsx passes — via a THIRD escape route. Its non-vacuity
                control is elements > WRAPPER_ELEMENTS || text, with WRAPPER_ELEMENTS = 2. Measured in
                that file's own harness:

                components-basic-span/default-badge elements=3 text="" drewSomething=true
                components-basic-span/secondary-badge elements=3 text="" drewSomething=true
                components-basic-span/status-badges elements=6 text="" drewSomething=true
                

                The empty badge's own host element is the third element, so a demo that draws nothing
                but an empty pill clears the control on the pill. That is distinct from the two escapes
                already recorded on finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805 (Radix's injected scrollbar stylesheet counting as text) and
                finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 (a large correct render hiding a small omission). ⇒ three different holes in the
                same control
                , which strengthens the [Decision] What instrument stops the container-declaration class regenerating — and do the remaining 45 get fixed before it lands? #6779-style argument that the instrument belongs
                per-renderer rather than in a stricter global threshold.

              3. Neither zod nor tsc: BaseSchema is .passthrough() and carries [key: string]: any, and
                children is declared on BaseSchema — so this is worse than the content case, where
                at least a declared-key check would bite. children is declared and unread, which is
                exactly the shape PR docs(context-menu): author the trigger card's text under the key ui:card reads #6807's "READ set is strictly stronger than the DECLARED set" note
                calls out, with variant as its example.

              ⛔ Why this is filed, not fixed — the repair key is a genuine decision

              The content members had one mechanical answer. This one has two, and they differ in kind:

              ⇒ this needs a ruling, not a sweep. Related to #6810 (the open needs-user-decision card
              asking whether this class gets a global instrument): this is the fifth rediscovery, the
              first one under a different key, and the first that the leak signature cannot find.

              Related

              #6810 (the decision card for this class) · #6805 · #6806 · #6788 · #6773 · #6771 (retiring
              body) · #5574 (the DOM-leak class the content members belong to and this one does not)

              Generated by Claude Code


              Generated by Claude Code

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                No labels
                No labels

                Type

                No type

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' finding(examples): seven catalog `badge` nodes author their text under `children`, which ui:badge never reads — three demos draw nothing at all · Issue #6829 · objectstack-ai/objectui · GitHub
                  Skip to content

                  finding(examples): seven catalog badge nodes author their text under children, which ui:badge never reads — three demos draw nothing at all #6829

                  Description

                  @claude

                  Found while implementing #6805 + #6806 (the scroll-area/badgecontent pair), by censusing
                  every badge node in the catalog to size that PR's corpus sweep. Out of that PR's fence — it
                  names the two badge nodes authoring content in sidebar-with-badges — so it is filed
                  rather than fixed.

                  Same defect class as #6773 / #6788 / #6805 / #6806, a different phantom key. Those four are
                  all content. This one is children, and that difference is why none of the existing
                  instruments see it.

                  Measured

                  packages/components/src/renderers/data-display/badge.tsx:32 renders
                  schema.label || renderChildren(schema.body). It reads label and body. It does
                  not read children — unlike card.tsx, which reads children || body.

                  Seven catalog badge nodes author children anyway. Census over all 431 fixtures, on
                  origin/main26896c689:

                  badge nodes 40 in 12 categories
                  keys authored on them: type 40 · variant 36 · label 31 · className 8 ·
                  children 7 · content 2
                  

                  The content 2 are #6806, repaired in PR for #6805/#6806. The children 7 are this card:

                  components-basic-span/default-badge children: [ text ]
                  components-basic-span/secondary-badge children: [ text ]
                  components-basic-span/status-badges .children[0..2] children: [ text ] (3 nodes)
                  core-schema-renderer/nested-schema-example ...children[0..1] children: "Nested" /
                  children: "Components"
                  

                  Rendered through the real SchemaRenderer the way the docs gallery renders them:

                  entry elements text
                  components-basic-span/default-badge 2 ""
                  components-basic-span/secondary-badge 2 ""
                  components-basic-span/status-badges 5 ""
                  core-schema-renderer/nested-schema-example 13 "Parent ComponentSibling Component
                  All rendered from a single schema tree"
                  

                  Three of those entries draw literally nothing — the whole demo is one empty pill. The
                  fourth renders its surrounding prose and silently drops both badges (Nested and
                  Components are absent from its text).

                  components-basic-span is a badge category: three of its entries are empty boxes on the
                  published page.

                  ⭐ Why every existing instrument is blind to this one

                  This is the part worth keeping. The content members of this class are caught, in principle,
                  by two different signals. This variant emits neither.

                  1. No DOM leak. The content members leak the authored string to the host element as
                    content="..." — the finding: the DOM-leak sweep never reaches packages/components/src/renderers/** — four layout/basic renderers still carry the unfixed spread #5574 signature, and what made finding(docs,examples): all five aspect-ratio docs demos author content, a key the renderer never reads — every demo on the published page renders an empty ratio box #6773/finding(examples): the basic-context-menu demo authors its trigger card under content, which ui:card never reads — the tile is an empty dashed box #6788/finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805/finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 findable by
                    attribute sweep. Measured here: leaked[content] = 0 on all four entries. children is a
                    pipeline key the renderer machinery consumes, so it never reaches the DOM. A leak sweep
                    cannot find this.

                  2. catalog-gallery-render.test.tsx passes — via a THIRD escape route. Its non-vacuity
                    control is elements > WRAPPER_ELEMENTS || text, with WRAPPER_ELEMENTS = 2. Measured in
                    that file's own harness:

                    components-basic-span/default-badge elements=3 text="" drewSomething=true
                    components-basic-span/secondary-badge elements=3 text="" drewSomething=true
                    components-basic-span/status-badges elements=6 text="" drewSomething=true
                    

                    The empty badge's own host element is the third element, so a demo that draws nothing
                    but an empty pill clears the control on the pill. That is distinct from the two escapes
                    already recorded on finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805 (Radix's injected scrollbar stylesheet counting as text) and
                    finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 (a large correct render hiding a small omission). ⇒ three different holes in the
                    same control
                    , which strengthens the [Decision] What instrument stops the container-declaration class regenerating — and do the remaining 45 get fixed before it lands? #6779-style argument that the instrument belongs
                    per-renderer rather than in a stricter global threshold.

                  3. Neither zod nor tsc: BaseSchema is .passthrough() and carries [key: string]: any, and
                    children is declared on BaseSchema — so this is worse than the content case, where
                    at least a declared-key check would bite. children is declared and unread, which is
                    exactly the shape PR docs(context-menu): author the trigger card's text under the key ui:card reads #6807's "READ set is strictly stronger than the DECLARED set" note
                    calls out, with variant as its example.

                  ⛔ Why this is filed, not fixed — the repair key is a genuine decision

                  The content members had one mechanical answer. This one has two, and they differ in kind:

                  ⇒ this needs a ruling, not a sweep. Related to #6810 (the open needs-user-decision card
                  asking whether this class gets a global instrument): this is the fifth rediscovery, the
                  first one under a different key, and the first that the leak signature cannot find.

                  Related

                  #6810 (the decision card for this class) · #6805 · #6806 · #6788 · #6773 · #6771 (retiring
                  body) · #5574 (the DOM-leak class the content members belong to and this one does not)

                  Generated by Claude Code


                  Generated by Claude Code

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    No labels
                    No labels

                    Type

                    No type

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' finding(examples): seven catalog `badge` nodes author their text under `children`, which ui:badge never reads — three demos draw nothing at all · Issue #6829 · objectstack-ai/objectui · GitHub
                      Skip to content

                      finding(examples): seven catalog badge nodes author their text under children, which ui:badge never reads — three demos draw nothing at all #6829

                      Description

                      @claude

                      Found while implementing #6805 + #6806 (the scroll-area/badgecontent pair), by censusing
                      every badge node in the catalog to size that PR's corpus sweep. Out of that PR's fence — it
                      names the two badge nodes authoring content in sidebar-with-badges — so it is filed
                      rather than fixed.

                      Same defect class as #6773 / #6788 / #6805 / #6806, a different phantom key. Those four are
                      all content. This one is children, and that difference is why none of the existing
                      instruments see it.

                      Measured

                      packages/components/src/renderers/data-display/badge.tsx:32 renders
                      schema.label || renderChildren(schema.body). It reads label and body. It does
                      not read children — unlike card.tsx, which reads children || body.

                      Seven catalog badge nodes author children anyway. Census over all 431 fixtures, on
                      origin/main26896c689:

                      badge nodes 40 in 12 categories
                      keys authored on them: type 40 · variant 36 · label 31 · className 8 ·
                      children 7 · content 2
                      

                      The content 2 are #6806, repaired in PR for #6805/#6806. The children 7 are this card:

                      components-basic-span/default-badge children: [ text ]
                      components-basic-span/secondary-badge children: [ text ]
                      components-basic-span/status-badges .children[0..2] children: [ text ] (3 nodes)
                      core-schema-renderer/nested-schema-example ...children[0..1] children: "Nested" /
                      children: "Components"
                      

                      Rendered through the real SchemaRenderer the way the docs gallery renders them:

                      entry elements text
                      components-basic-span/default-badge 2 ""
                      components-basic-span/secondary-badge 2 ""
                      components-basic-span/status-badges 5 ""
                      core-schema-renderer/nested-schema-example 13 "Parent ComponentSibling Component
                      All rendered from a single schema tree"
                      

                      Three of those entries draw literally nothing — the whole demo is one empty pill. The
                      fourth renders its surrounding prose and silently drops both badges (Nested and
                      Components are absent from its text).

                      components-basic-span is a badge category: three of its entries are empty boxes on the
                      published page.

                      ⭐ Why every existing instrument is blind to this one

                      This is the part worth keeping. The content members of this class are caught, in principle,
                      by two different signals. This variant emits neither.

                      1. No DOM leak. The content members leak the authored string to the host element as
                        content="..." — the finding: the DOM-leak sweep never reaches packages/components/src/renderers/** — four layout/basic renderers still carry the unfixed spread #5574 signature, and what made finding(docs,examples): all five aspect-ratio docs demos author content, a key the renderer never reads — every demo on the published page renders an empty ratio box #6773/finding(examples): the basic-context-menu demo authors its trigger card under content, which ui:card never reads — the tile is an empty dashed box #6788/finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805/finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 findable by
                        attribute sweep. Measured here: leaked[content] = 0 on all four entries. children is a
                        pipeline key the renderer machinery consumes, so it never reaches the DOM. A leak sweep
                        cannot find this.

                      2. catalog-gallery-render.test.tsx passes — via a THIRD escape route. Its non-vacuity
                        control is elements > WRAPPER_ELEMENTS || text, with WRAPPER_ELEMENTS = 2. Measured in
                        that file's own harness:

                        components-basic-span/default-badge elements=3 text="" drewSomething=true
                        components-basic-span/secondary-badge elements=3 text="" drewSomething=true
                        components-basic-span/status-badges elements=6 text="" drewSomething=true
                        

                        The empty badge's own host element is the third element, so a demo that draws nothing
                        but an empty pill clears the control on the pill. That is distinct from the two escapes
                        already recorded on finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805 (Radix's injected scrollbar stylesheet counting as text) and
                        finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 (a large correct render hiding a small omission). ⇒ three different holes in the
                        same control
                        , which strengthens the [Decision] What instrument stops the container-declaration class regenerating — and do the remaining 45 get fixed before it lands? #6779-style argument that the instrument belongs
                        per-renderer rather than in a stricter global threshold.

                      3. Neither zod nor tsc: BaseSchema is .passthrough() and carries [key: string]: any, and
                        children is declared on BaseSchema — so this is worse than the content case, where
                        at least a declared-key check would bite. children is declared and unread, which is
                        exactly the shape PR docs(context-menu): author the trigger card's text under the key ui:card reads #6807's "READ set is strictly stronger than the DECLARED set" note
                        calls out, with variant as its example.

                      ⛔ Why this is filed, not fixed — the repair key is a genuine decision

                      The content members had one mechanical answer. This one has two, and they differ in kind:

                      ⇒ this needs a ruling, not a sweep. Related to #6810 (the open needs-user-decision card
                      asking whether this class gets a global instrument): this is the fifth rediscovery, the
                      first one under a different key, and the first that the leak signature cannot find.

                      Related

                      #6810 (the decision card for this class) · #6805 · #6806 · #6788 · #6773 · #6771 (retiring
                      body) · #5574 (the DOM-leak class the content members belong to and this one does not)

                      Generated by Claude Code


                      Generated by Claude Code

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        No labels
                        No labels

                        Type

                        No type

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' finding(examples): seven catalog `badge` nodes author their text under `children`, which ui:badge never reads — three demos draw nothing at all · Issue #6829 · objectstack-ai/objectui · GitHub
                          Skip to content

                          finding(examples): seven catalog badge nodes author their text under children, which ui:badge never reads — three demos draw nothing at all #6829

                          Description

                          @claude

                          Found while implementing #6805 + #6806 (the scroll-area/badgecontent pair), by censusing
                          every badge node in the catalog to size that PR's corpus sweep. Out of that PR's fence — it
                          names the two badge nodes authoring content in sidebar-with-badges — so it is filed
                          rather than fixed.

                          Same defect class as #6773 / #6788 / #6805 / #6806, a different phantom key. Those four are
                          all content. This one is children, and that difference is why none of the existing
                          instruments see it.

                          Measured

                          packages/components/src/renderers/data-display/badge.tsx:32 renders
                          schema.label || renderChildren(schema.body). It reads label and body. It does
                          not read children — unlike card.tsx, which reads children || body.

                          Seven catalog badge nodes author children anyway. Census over all 431 fixtures, on
                          origin/main26896c689:

                          badge nodes 40 in 12 categories
                          keys authored on them: type 40 · variant 36 · label 31 · className 8 ·
                          children 7 · content 2
                          

                          The content 2 are #6806, repaired in PR for #6805/#6806. The children 7 are this card:

                          components-basic-span/default-badge children: [ text ]
                          components-basic-span/secondary-badge children: [ text ]
                          components-basic-span/status-badges .children[0..2] children: [ text ] (3 nodes)
                          core-schema-renderer/nested-schema-example ...children[0..1] children: "Nested" /
                          children: "Components"
                          

                          Rendered through the real SchemaRenderer the way the docs gallery renders them:

                          entry elements text
                          components-basic-span/default-badge 2 ""
                          components-basic-span/secondary-badge 2 ""
                          components-basic-span/status-badges 5 ""
                          core-schema-renderer/nested-schema-example 13 "Parent ComponentSibling Component
                          All rendered from a single schema tree"
                          

                          Three of those entries draw literally nothing — the whole demo is one empty pill. The
                          fourth renders its surrounding prose and silently drops both badges (Nested and
                          Components are absent from its text).

                          components-basic-span is a badge category: three of its entries are empty boxes on the
                          published page.

                          ⭐ Why every existing instrument is blind to this one

                          This is the part worth keeping. The content members of this class are caught, in principle,
                          by two different signals. This variant emits neither.

                          1. No DOM leak. The content members leak the authored string to the host element as
                            content="..." — the finding: the DOM-leak sweep never reaches packages/components/src/renderers/** — four layout/basic renderers still carry the unfixed spread #5574 signature, and what made finding(docs,examples): all five aspect-ratio docs demos author content, a key the renderer never reads — every demo on the published page renders an empty ratio box #6773/finding(examples): the basic-context-menu demo authors its trigger card under content, which ui:card never reads — the tile is an empty dashed box #6788/finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805/finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 findable by
                            attribute sweep. Measured here: leaked[content] = 0 on all four entries. children is a
                            pipeline key the renderer machinery consumes, so it never reaches the DOM. A leak sweep
                            cannot find this.

                          2. catalog-gallery-render.test.tsx passes — via a THIRD escape route. Its non-vacuity
                            control is elements > WRAPPER_ELEMENTS || text, with WRAPPER_ELEMENTS = 2. Measured in
                            that file's own harness:

                            components-basic-span/default-badge elements=3 text="" drewSomething=true
                            components-basic-span/secondary-badge elements=3 text="" drewSomething=true
                            components-basic-span/status-badges elements=6 text="" drewSomething=true
                            

                            The empty badge's own host element is the third element, so a demo that draws nothing
                            but an empty pill clears the control on the pill. That is distinct from the two escapes
                            already recorded on finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805 (Radix's injected scrollbar stylesheet counting as text) and
                            finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 (a large correct render hiding a small omission). ⇒ three different holes in the
                            same control
                            , which strengthens the [Decision] What instrument stops the container-declaration class regenerating — and do the remaining 45 get fixed before it lands? #6779-style argument that the instrument belongs
                            per-renderer rather than in a stricter global threshold.

                          3. Neither zod nor tsc: BaseSchema is .passthrough() and carries [key: string]: any, and
                            children is declared on BaseSchema — so this is worse than the content case, where
                            at least a declared-key check would bite. children is declared and unread, which is
                            exactly the shape PR docs(context-menu): author the trigger card's text under the key ui:card reads #6807's "READ set is strictly stronger than the DECLARED set" note
                            calls out, with variant as its example.

                          ⛔ Why this is filed, not fixed — the repair key is a genuine decision

                          The content members had one mechanical answer. This one has two, and they differ in kind:

                          ⇒ this needs a ruling, not a sweep. Related to #6810 (the open needs-user-decision card
                          asking whether this class gets a global instrument): this is the fifth rediscovery, the
                          first one under a different key, and the first that the leak signature cannot find.

                          Related

                          #6810 (the decision card for this class) · #6805 · #6806 · #6788 · #6773 · #6771 (retiring
                          body) · #5574 (the DOM-leak class the content members belong to and this one does not)

                          Generated by Claude Code


                          Generated by Claude Code

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            No labels
                            No labels

                            Type

                            No type

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); finding(examples): seven catalog `badge` nodes author their text under `children`, which ui:badge never reads — three demos draw nothing at all · Issue #6829 · objectstack-ai/objectui · GitHub
                              Skip to content

                              finding(examples): seven catalog badge nodes author their text under children, which ui:badge never reads — three demos draw nothing at all #6829

                              Description

                              @claude

                              Found while implementing #6805 + #6806 (the scroll-area/badgecontent pair), by censusing
                              every badge node in the catalog to size that PR's corpus sweep. Out of that PR's fence — it
                              names the two badge nodes authoring content in sidebar-with-badges — so it is filed
                              rather than fixed.

                              Same defect class as #6773 / #6788 / #6805 / #6806, a different phantom key. Those four are
                              all content. This one is children, and that difference is why none of the existing
                              instruments see it.

                              Measured

                              packages/components/src/renderers/data-display/badge.tsx:32 renders
                              schema.label || renderChildren(schema.body). It reads label and body. It does
                              not read children — unlike card.tsx, which reads children || body.

                              Seven catalog badge nodes author children anyway. Census over all 431 fixtures, on
                              origin/main26896c689:

                              badge nodes 40 in 12 categories
                              keys authored on them: type 40 · variant 36 · label 31 · className 8 ·
                              children 7 · content 2
                              

                              The content 2 are #6806, repaired in PR for #6805/#6806. The children 7 are this card:

                              components-basic-span/default-badge children: [ text ]
                              components-basic-span/secondary-badge children: [ text ]
                              components-basic-span/status-badges .children[0..2] children: [ text ] (3 nodes)
                              core-schema-renderer/nested-schema-example ...children[0..1] children: "Nested" /
                              children: "Components"
                              

                              Rendered through the real SchemaRenderer the way the docs gallery renders them:

                              entry elements text
                              components-basic-span/default-badge 2 ""
                              components-basic-span/secondary-badge 2 ""
                              components-basic-span/status-badges 5 ""
                              core-schema-renderer/nested-schema-example 13 "Parent ComponentSibling Component
                              All rendered from a single schema tree"
                              

                              Three of those entries draw literally nothing — the whole demo is one empty pill. The
                              fourth renders its surrounding prose and silently drops both badges (Nested and
                              Components are absent from its text).

                              components-basic-span is a badge category: three of its entries are empty boxes on the
                              published page.

                              ⭐ Why every existing instrument is blind to this one

                              This is the part worth keeping. The content members of this class are caught, in principle,
                              by two different signals. This variant emits neither.

                              1. No DOM leak. The content members leak the authored string to the host element as
                                content="..." — the finding: the DOM-leak sweep never reaches packages/components/src/renderers/** — four layout/basic renderers still carry the unfixed spread #5574 signature, and what made finding(docs,examples): all five aspect-ratio docs demos author content, a key the renderer never reads — every demo on the published page renders an empty ratio box #6773/finding(examples): the basic-context-menu demo authors its trigger card under content, which ui:card never reads — the tile is an empty dashed box #6788/finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805/finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 findable by
                                attribute sweep. Measured here: leaked[content] = 0 on all four entries. children is a
                                pipeline key the renderer machinery consumes, so it never reaches the DOM. A leak sweep
                                cannot find this.

                              2. catalog-gallery-render.test.tsx passes — via a THIRD escape route. Its non-vacuity
                                control is elements > WRAPPER_ELEMENTS || text, with WRAPPER_ELEMENTS = 2. Measured in
                                that file's own harness:

                                components-basic-span/default-badge elements=3 text="" drewSomething=true
                                components-basic-span/secondary-badge elements=3 text="" drewSomething=true
                                components-basic-span/status-badges elements=6 text="" drewSomething=true
                                

                                The empty badge's own host element is the third element, so a demo that draws nothing
                                but an empty pill clears the control on the pill. That is distinct from the two escapes
                                already recorded on finding(examples): all seven components-complex-scroll-area demos author their body under content, which ui:scroll-area never reads — every box on the page is empty #6805 (Radix's injected scrollbar stylesheet counting as text) and
                                finding(examples): sidebar-with-badges authors its two counts under content, which ui:badge never reads — the badges render empty #6806 (a large correct render hiding a small omission). ⇒ three different holes in the
                                same control
                                , which strengthens the [Decision] What instrument stops the container-declaration class regenerating — and do the remaining 45 get fixed before it lands? #6779-style argument that the instrument belongs
                                per-renderer rather than in a stricter global threshold.

                              3. Neither zod nor tsc: BaseSchema is .passthrough() and carries [key: string]: any, and
                                children is declared on BaseSchema — so this is worse than the content case, where
                                at least a declared-key check would bite. children is declared and unread, which is
                                exactly the shape PR docs(context-menu): author the trigger card's text under the key ui:card reads #6807's "READ set is strictly stronger than the DECLARED set" note
                                calls out, with variant as its example.

                              ⛔ Why this is filed, not fixed — the repair key is a genuine decision

                              The content members had one mechanical answer. This one has two, and they differ in kind:

                              ⇒ this needs a ruling, not a sweep. Related to #6810 (the open needs-user-decision card
                              asking whether this class gets a global instrument): this is the fifth rediscovery, the
                              first one under a different key, and the first that the leak signature cannot find.

                              Related

                              #6810 (the decision card for this class) · #6805 · #6806 · #6788 · #6773 · #6771 (retiring
                              body) · #5574 (the DOM-leak class the content members belong to and this one does not)

                              Generated by Claude Code


                              Generated by Claude Code

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                No labels
                                No labels

                                Type

                                No type

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions