pub struct ImeState {
pub active: bool,
pub editing: EditingState,
pub caret: Option<Rect>,
pub content_type: ImeContentType,
pub suppress_soft_keyboard: bool,
}Expand description
The IME-relevant surface a focused editable widget publishes for the shell.
Written by the focused widget through EventCtx::publish_ime_state, it
bubbles up the focus chain and is stored on crate::app::RenderRoot, where
the shell reads it via crate::app::RenderRoot::ime_state to drive the
platform IME (winit set_ime_cursor_area, Android updateSelection, iOS
inputDelegate). See the module docs for the index boundary rule.
§editing carries the real text, even for a secret field
content_type marks a field secret; it does not
redact editing. That is deliberate: this struct is one
half of a bidirectional state-sync mirror (see docs/CODE_STANDARDS.md’s
state-sync rule) — the platform keeps a local Editable/UITextInput mirror
seeded from these exact fields and hands a whole reconciled
EditingState back through ImeEvent::ApplyEditingState. Publishing
redacted or masked text would desynchronize that mirror (the platform would
compute deletions/replacements against text the widget does not have, and
would echo the mask back as the field’s new value), and it would not close
the leak anyway: the keyboard process is where the characters originate.
What a hint does close is the suggestion strip reading the field’s text and
the IME persisting it to a learned-word dictionary.
Residual exposure: the plaintext still crosses the FFI seam into the
platform IME. A hostile or non-compliant third-party keyboard can read it.
That is unavoidable on both mobile platforms short of not using the platform
IME at all. As partial mitigation, this type’s fmt::Debug redacts the
text whenever the content type is secret, so a trace log never carries it.
Fields§
§active: boolWhether the focused widget currently wants IME active.
editing: EditingStateThe current editing state (UTF-16 indexed at this shell-facing surface).
caret: Option<Rect>The caret rectangle in logical coordinates, for IME candidate placement.
content_type: ImeContentTypeWhat kind of content the field holds, so the shell can configure the
platform IME. Defaults to ImeContentType::Normal — a field that says
nothing behaves exactly as it did before this hint existed.
suppress_soft_keyboard: boolWhether the field wants the platform input surface without an on-screen keyboard.
A field whose text cannot be changed is still focusable and copyable
(Material 3 and Apple’s HIG both keep it so), and copying is exactly
what needs the surface: the web overlay <input>’s DOM copy
listener, Android’s InputConnection and iOS’s first responder are
each the route a clipboard verb travels, and all three exist only while
active holds. What such a field does not need is
somewhere to type — so this asks the shell to keep the surface wired and
suppress the soft keyboard it would otherwise raise.
Defaults to false — a field that says nothing behaves exactly as it
did before this hint existed. It says nothing about an inactive surface
(there is no keyboard up to suppress), and a shell with no on-screen
keyboard of its own has nothing to do for it.
Trait Implementations§
Source§impl Debug for ImeState
impl Debug for ImeState
Source§fn fmt(&self, f: &mut Formatter<'_>) -> Result
fn fmt(&self, f: &mut Formatter<'_>) -> Result
Hand-written so a secret field’s text never reaches a log.
Everything except EditingState::text prints as derived; for a secret
content_type the text is replaced by
<redacted> (no length, which would itself leak).