Custom themes override nine of twenty-one token roles #202
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#202
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Follow-on from #170, which took
design/tokens.yamlfrom nine roles per modeto twenty-one. A household's custom theme still overrides only the original
nine, so the twelve new roles fall back to the family theme's values — which can
be from the wrong end of the light/dark axis entirely.
The defect
A custom theme is a map of overrides stored on the user record
(
UserSettings.custom_tokens,map<string, string>) and applied over a basefamily variant in three places:
web/src/theme/theme.tsx:144—TOKEN_NAMES--radius, by handweb/src/pages/Settings.tsx:1361—WORKSHOP_TOKENSanchor/deriverulesandroid/.../ui/Theme.kt:100—applyCustomTokensNone of them knows about
surface-raised,surface-sunken,ink-muted,border,border-strong,error,error-surface,destructive,on-destructive,warning,on-warningoron-celebrate.So a household that builds a dark custom theme on top of a light family keeps
that family's light
surface-raisedanderror-surface. An in-place editbox would be a pale panel on a dark card, and the invalid-row ring would sit on
a background it was never checked against. The generator guarantees WCAG AA for
every pair it emits; a custom theme currently escapes that guarantee for twelve
of twenty-one roles, and the failure is silent.
Nothing is broken today only because no component consumes the new roles yet.
The first UI ticket that does — #171's row grammar, which needs
surface-raised,border-strongand the error pair — makes it visible.What to build
The machinery already exists and is good:
WORKSHOP_TOKENSmarks a few tokensas
anchor(the person picks them) and derives the rest with small functions —mixHexfor stepping a colour toward another,bestTextOnfor picking readableink over a fill. Extend that rather than growing the editor.
anchors. The surfaces step off
--surface/--cardthe way--cardalready steps off
--surface; the borders walk--linetoward--ink;erroranddestructivecome from--danger; the on-fill inks go throughbestTextOn.--warningis the one with no anchor to derive from — decidewhether it becomes a fourth anchor the person picks, or is derived from
--celebrate's hue while staying a separate value (it must never aliascelebrate; that is the rule #170 was built on).default. The workshop asks a household for a handful of decisions, not
twenty-one.
over authored values and cannot see a custom theme. A person can pick any
two colours, so the derive rules have to clamp: an
on-warningderived overa chosen
warningmust clear 4.5:1, andborder-strongovercardmustclear the 3:1 non-text floor #170 introduced. Where a clamp cannot reach the
threshold, say so in the editor rather than shipping an unreadable pair.
the same on both surfaces.
theme.tsx's comment aboveTOKEN_NAMESdescribes it as "the tokenvocabulary defined in design/tokens.yaml" — that is now inaccurate whichever
way this lands.
Not a data problem
custom_tokensis a string map, so new keys need no proto change and nomigration: an old record simply carries fewer keys and the derive rules fill the
rest. Existing custom themes keep their nine chosen values.
Acceptance
Decided:
--warningbecomes a fourth anchor.The workshop asks the household for it alongside background, text and accent,
rather than deriving it. Deriving loses exactly where it matters: a family whose
--celebrateis pink or blue has nothing warm to turn toward, which is why thebuilt-in themes needed hand-tuning for
cvd-red-tealandmonoin #170.A picked colour still needs clamping —
on-warningover it must clear 4.5:1,and the editor says so when a choice cannot get there, rather than shipping an
unreadable pair.
The other eleven roles stay derived and invisible: the workshop asks for four
decisions, not twenty-one.