#[non_exhaustive]pub enum ImeContentType {
Normal,
Password,
NoSuggestions,
Terminal,
}Expand description
The event-pass/IME-surface EditingState — see this module’s own docs
for the split against text::EditingState,
frust_text::editor’s distinct, byte-indexed type. ImeContentType is
the input-purpose hint an editable widget publishes on its ImeState so
a shell can lock a secret field’s keyboard down.
What kind of content a focused editable field holds — the hint a widget
publishes so each shell can configure the platform input method.
This is the framework’s input-purpose vocabulary: renderer- and platform-neutral names a widget states its intent in, which each shell maps onto its own host API. It is deliberately tiny — it exists to let a secret field tell the platform it is secret, not to model every keyboard layout.
§Why this exists (security, not ergonomics)
Visual masking (TextInput::obscured) hides the glyphs the app draws; it
says nothing to the input method. A stock soft keyboard given no hint will
happily render the field’s text in its suggestion strip above the masked
field, and may commit it to its persistent learned-word dictionary. Only a
content-type hint suppresses that; an accessibility Role::PasswordInput
does not.
§Platform mapping
Each shell owns its own constants (core holds no platform integers). The intended mapping, which downstream shell work must honour:
| Variant | Android (InputType / EditorInfo.imeOptions) | iOS (UITextInputTraits) | Desktop (winit) |
|---|---|---|---|
Normal | TYPE_CLASS_TEXT | platform defaults | ImePurpose::Normal |
Password | TYPE_CLASS_TEXT | TYPE_TEXT_VARIATION_PASSWORD, plus TYPE_TEXT_FLAG_NO_SUGGESTIONS and IME_FLAG_NO_PERSONALIZED_LEARNING | isSecureTextEntry = true, textContentType = .password, autocorrectionType = .no, spellCheckingType = .no, plus smart-punctuation suppression (see Terminal) | ImePurpose::Password |
NoSuggestions | TYPE_CLASS_TEXT | TYPE_TEXT_FLAG_NO_SUGGESTIONS, plus IME_FLAG_NO_PERSONALIZED_LEARNING | autocorrectionType = .no, spellCheckingType = .no, plus smart-punctuation suppression | no equivalent — ImePurpose::Normal |
Terminal | TYPE_CLASS_TEXT | TYPE_TEXT_FLAG_NO_SUGGESTIONS, plus IME_FLAG_NO_PERSONALIZED_LEARNING (same as NoSuggestions) | isSecureTextEntry = false, autocorrectionType = .no, spellCheckingType = .no, smartQuotesType = .no, smartDashesType = .no, smartInsertDeleteType = .no, autocapitalizationType = .none, textContentType = nil | ImePurpose::Terminal |
Sources: Android android.text.InputType / android.view.inputmethod.EditorInfo
and Apple UITextInputTraits reference docs, retrieved 2026-08-01.
Unsupported is a first-class outcome. winit 0.30’s
Window::set_ime_purpose is documented as unsupported on iOS/Android/Web/
Windows/X11/macOS/Orbital (Wayland text-input-v3 is the only implementation),
so the desktop shell may legitimately honour nothing here. A shell that
cannot express a hint drops it — it must never refuse to publish, and core
never asserts that a hint took effect.
§Matching rule for shells
This enum is #[non_exhaustive]: adding a variant later (numeric password,
email, one-time code…) must not break a shell. So a shell branches its
security behaviour on is_secret /
suppresses_suggestions, never on a variant
match with a _ => fallback — a catch-all arm would silently downgrade a
future secret variant to a non-secret keyboard, which is exactly the leak
this type exists to close. Variant matching is fine for the cosmetic
choice (which keyboard layout to request).
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
Normal
No hint: ordinary text, platform defaults (suggestions, autocorrect and personalized learning all as the user configured them).
The default, and what every field publishes unless it opts in.
Password
Secret text (password / passphrase / PIN entered as text).
The shell must request secure entry and suppress suggestions and personalized learning.
NoSuggestions
Non-secret text that must not be autocorrected, suggested, or learned (recovery codes, identifiers, usernames).
Distinct from Password: the platform does not
switch to secure entry, so autofill/reveal-last-character behaviour is
unchanged; only the suggestion/learning channel is closed.
Terminal
A raw byte-entry surface (a terminal/shell keystroke source): no suggestion strip, no autocorrect, no smart quotes/dashes/insert-delete, no autocapitalization. Text is not masked — this is not a secret field, it is a field where every character the user typed must reach the app byte-for-byte with zero platform “correction” applied to it.
The defect this closes is the same class Password
closes for secrets: a smart keyboard silently substituting " for a
curly quote or -- for an em dash corrupts a shell command exactly as
it corrupts a password, just without the confidentiality angle. Distinct
from NoSuggestions: that variant suppresses the
suggestion/learning channel only, while Terminal additionally
suppresses smart punctuation and autocapitalization, both of which
silently rewrite the text a suggestion-only hint leaves untouched.
Implementations§
Source§impl ImeContentType
impl ImeContentType
Sourcepub fn is_secret(self) -> bool
pub fn is_secret(self) -> bool
Whether the field holds a secret the platform must treat as such
(secure entry on iOS, a password InputType variation on Android).
Shells gate secure-entry configuration on this, not on a variant match (see the type docs’ matching rule).
This predicate and suppresses_suggestions
match exhaustively (no _ arm) on purpose: adding a variant to this enum
is a compile error here until it is classified as secret or not.
Sourcepub fn suppresses_suggestions(self) -> bool
pub fn suppresses_suggestions(self) -> bool
Whether the platform must suppress its suggestion strip, autocorrect, and persistent word learning for this field.
True for every secret content type and for
NoSuggestions and Terminal.
Trait Implementations§
Source§impl Clone for ImeContentType
impl Clone for ImeContentType
Source§fn clone(&self) -> ImeContentType
fn clone(&self) -> ImeContentType
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreimpl Copy for ImeContentType
Source§impl Debug for ImeContentType
impl Debug for ImeContentType
Source§impl Default for ImeContentType
impl Default for ImeContentType
Source§fn default() -> ImeContentType
fn default() -> ImeContentType
impl Eq for ImeContentType
Source§impl Hash for ImeContentType
impl Hash for ImeContentType
Source§impl PartialEq for ImeContentType
impl PartialEq for ImeContentType
impl StructuralPartialEq for ImeContentType
Auto Trait Implementations§
impl Freeze for ImeContentType
impl RefUnwindSafe for ImeContentType
impl Send for ImeContentType
impl Sync for ImeContentType
impl Unpin for ImeContentType
impl UnsafeUnpin for ImeContentType
impl UnwindSafe for ImeContentType
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<T> Brush for T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Downcast for Twhere
T: Any,
impl<T> Downcast for Twhere
T: Any,
Source§fn into_any(self: Box<T>) -> Box<dyn Any>
fn into_any(self: Box<T>) -> Box<dyn Any>
Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>. Box<dyn Any> can
then be further downcast into Box<ConcreteType> where ConcreteType implements Trait.Source§fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
Rc<Trait> (where Trait: Downcast) to Rc<Any>. Rc<Any> can then be
further downcast into Rc<ConcreteType> where ConcreteType implements Trait.Source§fn as_any(&self) -> &(dyn Any + 'static)
fn as_any(&self) -> &(dyn Any + 'static)
&Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &Any’s vtable from &Trait’s.Source§fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
&mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &mut Any’s vtable from &mut Trait’s.Source§impl<T> DowncastSync for T
impl<T> DowncastSync for T
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.