Skip to content

fix(components): a field:-prefixed secret field fails closed instead of rendering clear text (#5322) - #5374

Merged
os-support-ai merged 1 commit into
mainfrom
claude/issue-5322-prefixed-field-native-input
Aug 20, 2026
Merged

fix(components): a field:-prefixed secret field fails closed instead of rendering clear text (#5322)#5374
os-support-ai merged 1 commit into
mainfrom
claude/issue-5322-prefixed-field-native-input

Conversation

@os-support-ai

Copy link
Copy Markdown
Collaborator

Fixes#5322

The defect, re-measured at this branch point

main at f2e11ae6f. On the built-in path (@object-ui/fields not registered), rendered through the real form renderer:

type registry hit rendered type attrs
field:password false text ["class","id","aria-describedby","aria-invalid","type","name"]
field:email false text (same)
password true password (PR5326 behaviour)
email true email (PR5326 behaviour)

A field:-prefixed id resolves nothing, takes renderFieldComponent's default arm, and misses NATIVE_INPUT_FIELD_TYPES because that table is keyed on the raw type. mapFieldTypeToFormType emits the prefixed id for every object-derived form, so this is the normal path: an object-derived password field put the secret on screen in clear text, and an object-derived email field lost its native keyboard and validation.

Pre-existing. The table is keyed on the raw type, so the prefixed spelling never matched it — the same reading was taken on origin/main before #5254 landed. #5254 / PR5326 neither introduced nor fixed this.

The shape chosen, and why

Triage ruled: "the unregistered-widget default must respect the declared input type, or refuse to render the value rather than degrade to clear text", with "for password specifically, prefer masking/refusal over best-effort rendering". Both limbs are used — on the spelling where each is correct, because the two spellings do not mean the same thing:

  • A barepassword / email is a declared input type on the built-in path. It claims no registered widget; this branch is its intended home and its native input is the correct rendering, not a degrade. Untouched.
  • A field:-prefixed id is a registry key. Reaching the default arm with one proves an unmet contract: the app declares a widget that is not registered.

So:

spellingbeforeafter
field:passwordtype="text" — secret in clear textrefusal — no input, no value in the DOM
field:emailtype="text"type="email"
passwordtype="password"type="password" (unchanged)
emailtype="email"type="email" (unchanged)

Why refusal and not masking for field:password. Masking alone closes the leak, and it is exactly what the bare spelling does. It is not enough here, because here we additionally know the app shipped without the widget it declares: a masked box would invite the user to type a secret into a form whose password widget — strength meter, confirm pair, reveal toggle, submit handling — is absent, in a control that looks like it worked. The refusal is an inline role="alert" naming the missing widget id, plus a console.error whose text doubles as the fix instruction (registerAllFields()), mirroring RetiredFieldTombstone in packages/fields and this file's own spec-vocabulary boundary (#3090). Nothing is thrown — one unrenderable field must not take down the rest of a record form.

Why field:email gets the other limb. No leak, and the ruling's first limb applies directly: respect the declared type. Turning every unregistered field:* id into a refusal would change field:currency, field:qrcode and every other type this card neither moved nor measured, and would break every app that renders forms without registering fields.

Deliberately narrow: only password refuses, only under the field: namespace, and a registered field:password widget still wins. A ui:-qualified id renders exactly as it does today.

No new authorable key

The accept set is unchanged — no metadata key is declared, read, or widened. NATIVE_INPUT_FIELD_TYPES is now keyed on the declared type (normalizeFieldType, already in this file) instead of the raw one; the refusal keys on the field: prefix plus a two-line SECRET_FIELD_TYPES set. This narrows what renders; it accepts nothing new.

Verification

Pinned on the rendered output, not the resolver — the whole defect is that a resolver returning nothing still produced a plausible-looking control.

New file: packages/components/src/renderers/form/__tests__/form-prefixed-field-native-input.test.tsx, 16 tests, covering both spellings and both types plus the no-collateral cases (a registered field:password widget wins; field:currency still renders its text box; builtin input untouched; the declared ceiling still caps).

Verified at 6a668d777:

pnpm exec vitest run packages/components/src/renderers/form/__tests__/form-prefixed-field-native-input.test.tsx
Test Files 1 passed (1) Tests 16 passed (16)
pnpm exec vitest run packages/components/src/renderers/form packages/components/src/__tests__/form-renderers.test.tsx
Test Files 50 passed (50) Tests 352 passed (352)
pnpm exec vitest run packages/plugin-form packages/plugin-detail packages/fields
Test Files 250 passed (250) Tests 3200 passed (3200)
pnpm --filter @object-ui/components type-check exit 0
pnpm exec eslint (the two changed files) 0 errors
node scripts/check-control-bytes.mjs OK
check:i18n-keys / i18n-drift / doc-types / phantom-deps / self-import all rc=0

Run from the repo root with no -- before the paths, per scripts/vitest-invocation-guard.mjs.

Reverse verification

form.tsx reverted to origin/main with the new test file kept, then re-run:

Test Files 1 failed (1) Tests 6 failed | 10 passed (16)
× renders NO input at all
AssertionError: expected an input element to be null
× renders a visible refusal naming the widget that is missing
× keeps a seeded secret out of the DOM entirely
Received: "… type="text" value="hunter2" name="pw3" …"
× writes the fix instruction to the console
× does not take the rest of the form down with it
× renders the native email input, still named and labelled
AssertionError: expected 'text' to be 'email'

type="text" appears in the failure text on the field:password legs, and the seeded-secret leg prints the pre-fix DOM carrying value="hunter2" in clear text. The 10 that stay green are the bare-spelling pins and the no-collateral cases — i.e. the file would also catch a fix that traded one spelling for the other. form.tsx was restored from the commit afterwards (git checkout HEAD -- …), verified byte-identical by an empty git diff HEAD.

Build artifacts

None on any leg. The root vitest.config.mts aliases every @object-ui/* specifier to that package's src/, and the renderer under test is imported through a relative path, so no dist/ sits between the edit and the thing under test. The dependency closure (pnpm --filter '@object-ui/components^...' build) was built only because type-check resolves @object-ui/core and @object-ui/types through their published .d.ts — without it that leg fails with TS2307 Cannot find module, which reads like a source error and is not one.

check:doc-snippets was not run locally: it refuses to start until every package it resolves against has a built dist/, unrelated to this change. CI builds first and runs it there.

Notes

  • The visible refusal is developer copy, not end-user copy (an app in this state is misconfigured), so it is plain English with no i18n key — the same call RetiredFieldTombstone makes.
  • +1 eslint warning on form.tsx (react-refresh/only-export-components, for the new component), the same warning the two neighbouring built-in-branch components already carry. --max-warnings is deliberately unset in lint.yml.

Generated by Claude Code

…d of rendering clear text (#5322)
On the built-in path the `field:`-prefixed widget id resolves nothing and takes
the form renderer's `default` input branch, whose native-input table was keyed on
the raw `type`. The prefixed spelling missed it and rendered `type="text"` —
`mapFieldTypeToFormType` emits that id for every object-derived form, so an
object-derived password field put the secret on screen in clear text.
- `field:password` now refuses: no input, no value in the DOM, an inline
`role="alert"` naming the missing widget and a `console.error` carrying the fix.
- `field:email` renders the native email input (the table is keyed on the
declared type, prefix stripped).
- The bare `password` / `email` spellings are untouched.
Pre-existing, not a regression from #5254.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RV6yuVCxymHYE16PL9vQkE
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)25.3 KB350 KB
Entry fileindex-BInyohVQ.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)9.83KB3.70KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)6.35KB2.43KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.94KB113.61KB
core (index.js)4.11KB1.62KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)159.80KB44.34KB
fields (index.js)237.07KB59.46KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.42KB1.39KB
i18n (pickLocalized.js)3.69KB1.73KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)30.51KB7.57KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.35KB3.31KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.42KB1.42KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.81KB0.83KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.75KB18.37KB
plugin-chatbot (index.js)181.21KB43.14KB
plugin-dashboard (index.js)128.07KB32.77KB
plugin-designer (index.js)212.39KB42.83KB
plugin-detail (index.js)241.46KB60.56KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)124.19KB30.20KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)197.30KB53.06KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.66KB27.13KB
plugin-map (index.js)20.08KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.52KB20.67KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)36.10KB12.26KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)1.45KB0.83KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.08KB1.53KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-support-ai
os-support-ai marked this pull request as ready for review August 20, 2026 02:53
@os-support-ai
os-support-ai added this pull request to the merge queueAug 20, 2026
Merged via the queue into main with commit aff10e2Aug 20, 2026
22 checks passed
@os-support-ai
os-support-ai deleted the claude/issue-5322-prefixed-field-native-input branch August 20, 2026 02:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

A field:-prefixed password / email field renders type=&quot;text&quot; when its widget is not registered — a secret shown in clear text

1 participant

@os-support-ai