Skip to main content

makeover_immediate/
lib.rs

1//! The immediate-mode renderer for [`makeover_layout`].
2//!
3//! <!-- wiki: makeover-immediate -->
4//!
5//! Named for the mode, not the library, the way `makeover-tui` is named for
6//! the target and not for ratatui. Immediate mode is the constraint that
7//! actually separates this renderer from the other two, and egui is the
8//! backend it is written against.
9//!
10//! It is the harshest renderer the description has to survive: no
11//! `box-shadow`, no `inset`, no cascade, no retained tree to mutate, and
12//! `Visuals.widgets.*.bg_stroke` is a single stroke with no per-side control.
13//! A two-tone lit edge is not something egui can be configured into producing,
14//! so it gets painted by hand here, once, instead of in every consuming app.
15//!
16//! # What this crate does and does not own
17//!
18//! It owns the *expression*: two mitred polylines for a bevel and a `Frame`
19//! for a filled region. It owns no colours, no sizes and no substitutions:
20//! makeover derives `surface-well` and every consumer reads the real token.
21//! [`Palette`] is supplied by the caller,
22//! already resolved, and every radius, margin and stroke width arrives in
23//! [`FrameStyle`].
24//!
25//! That split is why the crate has no dependency on `makeover` itself: the app
26//! already resolves a theme, and coupling a renderer to a colour crate's
27//! version would buy nothing.
28//!
29//! # The cascade is the real difference
30//!
31//! A stylesheet can say "a pressed button inverts its bevel" once and let the
32//! cascade carry it. An immediate-mode renderer has nowhere to put that, so
33//! every call site decides. [`makeover_layout::Depth::pressed`] is what keeps
34//! the decision from being re-derived per widget.
35//!
36//! # Overlays
37//!
38//! [`Palette::cast`] is what overlaying means in immediate mode. [`frame`] hands
39//! the cast shadow to the `egui::Frame` for any depth whose fill is
40//! [`Fill::Overlay`], keyed off the fill rather than the variant.
41//!
42//! # The table
43//!
44//! [`table`] draws `makeover_layout::CellPart`. Two things it forces, both named
45//! where they land:
46//!
47//! - **`egui_extras`**, this crate's one dependency past egui. egui has no
48//!   table, and `Grid` gives no per-column sizing, no sticky header and no
49//!   scroll sync. A third answer here would reimplement that crate worse.
50//! - **[`Palette::action`]**, on the footing [`Palette::content`] sits on: a
51//!   link in a cell needs the action intent.
52//!
53//! Narrowing works differently from the terminal's and the module header says
54//! why: a content column cannot be measured before the app's closure has drawn
55//! it, so `egui_extras` sizes it and the declared floor budgets it.
56//!
57//! Three things are host idiom rather than description, which is why they land
58//! here and not in `makeover-layout`, and all three are answered on a handle the
59//! app never sees: the `egui_extras` row and builder this crate owns. That is
60//! [`table::cell`]'s reasoning again: what the app cannot reach, the renderer
61//! owes it.
62//!
63//! - **A selected row.** [`table::Body::selected`], a predicate asked per row,
64//!   because `set_selected` is a method on the row. Without it a file list has
65//!   no way to show what is selected, which is most of what a file list does.
66//! - **Scrolling a row into view.** [`table::Body::scroll_to`], because
67//!   `scroll_to_row` is a method on the builder. A keyboard cursor that moves
68//!   off-screen and stays there is the bug this prevents.
69//! - **Dragging a divider.** [`table::TableStyle::resizable`], which is a knob
70//!   because egui_extras offers two settings here and a renderer can honestly
71//!   make either choice.
72//!
73//! Cells are centred on the row's centre line, always, because there is no
74//! second honest answer and egui's own default (top-aligned) is the one thing it
75//! cannot be. That is not a knob.
76//!
77//! [`table::Body`] is also what splits a table's per-frame facts from its
78//! description and from its style. A row count, a selection and a scroll request
79//! are none of them style, and none of them survive the frame.
80//!
81//! # The nodes that are not fields, tables or frames
82//!
83//! [`widget`] draws a meter, a token, a control and a figure. The four are
84//! ordinary nodes, so without them a screen walk has to draw them itself, one
85//! copy per consumer.
86//!
87//! [`Palette`] carries the three status intents together rather than one per
88//! widget, for the reason [`Palette::fill`] is an `Option`: `Tone` is five
89//! members wide, and a resolver missing one has to invent a colour, which is a
90//! substitution this crate does not make.
91//! # Forms
92//!
93//! The field vocabulary sits on top of the depth vocabulary:
94//! [`makeover_layout::Field`] rendered to egui widgets, in [`field`], and a set
95//! of them laid down a column in [`group`].
96//!
97//! `makeover-webview`'s form emitter is the precedent, followed rather than
98//! re-derived, including the parts that are bug fixes: a
99//! select handed a value none of its options carries keeps that value visible
100//! instead of silently reading as the first option, which is a save-the-wrong-
101//! thing bug goingson hit for real.
102//!
103//! What differs is forced by the mode and not chosen:
104//!
105//! - **The value arrives as a `&mut`.** [`Filling`] borrows the app's own field
106//!   and the widget writes through it. There is no DOM to read back out of,
107//!   which is also why the description deliberately does not carry the value.
108//! - **A text control is drawn as a well and a select is not.** The description
109//!   holds that a well is for anything the user looks *into*, and a text field
110//!   is its own example; a select and a checkbox are pressed rather than looked
111//!   into, so they keep egui's own control painting.
112//! - **Focus is not describable, and egui owns all of it here.** **Reach**,
113//!   **focus** and the **focus ring** are this renderer's three answers and
114//!   egui already has all three: its own id stack decides what is reachable,
115//!   its own state decides what holds the keyboard, and it paints exactly one
116//!   ring. A description states none of them, and drawing a second ring on top
117//!   of egui's would break the one-ring rule. The terms
118//!   are defined once in `makeover_layout`'s crate header, "Reach, focus and
119//!   the focus ring". [`makeover_layout::State::Disabled`] *is* drawn, because
120//!   egui has no opinion about it until told.
121//! - **App-level chrome is not drawn here, and it is not this crate's to
122//!   draw.** `quasi-router` names the affordances that outlive one screen: a
123//!   `Chrome` of key bindings, and an `Outcome::Over` for a screen drawn over
124//!   another. Both are answered by `quasi-webview` and `quasi-tui`, and neither
125//!   is answerable here, because this crate depends on `makeover-layout` and
126//!   not on `quasi-router` — it is the peer of `makeover-webview` and
127//!   `makeover-tui`, one layer below the renderers that consume a `Screen`.
128//!   What is missing is the egui crate at *that* layer, which does not exist:
129//!   nothing renders a quasi `Screen` in egui at all, and chrome is one item on
130//!   the list such a crate would owe. Said here because this is where a reader
131//!   looks for it, and because the silent version reads as "egui does not need
132//!   a palette" rather than "nobody has built the renderer yet".
133
134//! # An interval is a sixth control shape
135//!
136//! [`FieldKind::Interval`] is drawn as `Control::Spanned`: two drag boxes on one
137//! row with the word `to` between them.
138//!
139//! - **Dragged rather than typed**, because that is what these controls already
140//!   were. audiofiles' six filter axes are `DragValue` pairs sharing an extent,
141//!   a speed and a suffix, and describing them into two text boxes would be a
142//!   port that cost the app a control.
143//! - **One row, not two wells stacked.** Two wells are two questions on screen
144//!   whatever the description says, and the arrangement is the whole content of
145//!   the kind.
146//! - **An empty end reads as the bound it stands for.** An unset minimum sits
147//!   on the low edge and stores no filter, which is what the shipped control
148//!   did; egui's `DragValue` has no empty state, and a text box in its place
149//!   would cost the app a control. With no extent to fall back on it reads
150//!   zero -- the one number this renderer invents, invented where the
151//!   description declined to say anything.
152//! - **The word rather than a dash**, which on a signed axis is a minus sign.
153//!   audiofiles filters loudness in dBFS.
154//!
155//! `Axis` holds the four facts both boxes share, because they are one axis:
156//! reading `min`, `max`, `step` and `unit` once is what stops the two ends
157//! drifting apart.
158//!
159//! # A number draws its unit
160//!
161//! [`Field::unit`], and this host is the one with somewhere better than the
162//! label to put it: egui's `Slider` draws a suffix beside its readout.
163//!
164//! So a slider takes it as a suffix, inside the control. A typed number has no
165//! readout of its own and takes it as a muted label after the box. Every other
166//! kind ignores it, and the description says which those are --
167//! `FieldKind::measurable`, rather than a `matches!` kept here.
168//!
169//! # The slider's track is a curve
170//!
171//! `makeover-layout` says what a slider is: a fraction and a function
172//! taking numbers to numbers, with `min` and `max` being `f(0)` and `f(1)`
173//! rather than the control's extent. This host has the easiest job of the
174//! three, because egui already has the control -- `Slider::logarithmic` is a
175//! constant-ratio track, so the mapping is a builder call rather than an
176//! arithmetic of its own.
177//!
178//! Two things worth knowing. The granularity rides on the curve, so a range
179//! reads `Field::curve.step()` and every other kind reads `Field::step`; the
180//! step is in the value's own units under either curve, so the display
181//! precision derives from it directly. And the fallback for a ratio curve
182//! across zero is asked of `Curve::is_ratio` rather than matched on the
183//! variant, so this renderer and a terminal cannot disagree about when a
184//! logarithmic request is honoured.
185//!
186//! # The slider, the unanswered chooser, and the option that is not offered
187//! yet
188//!
189//! Three things a description can say here.
190//!
191//! - **[`FieldKind::Range`] is a fifth control shape**, `Control::Slid`, drawn
192//!   with egui's `Slider`. A range missing an end falls back to a well rather
193//!   than to invented bounds, which is what
194//!   `makeover_layout::Field::bounded` is for.
195//! - **`Field::placeholder` reads on a chooser**, so a select with nothing
196//!   chosen does not show an empty box.
197//! - **`Choice::unavailable` is drawn rather than dropped.** The option stays
198//!   in the list, inert, with its precondition beside it instead of behind a
199//!   hover — a greyed row with no reason reads as a dead end, which is the
200//!   whole finding.
201//! - **`Choice::detail` is drawn under the option in a
202//!   radio group and inside the row in a combo.** A closed chooser hides its
203//!   list, so everything an option carries has to travel with its row; a group
204//!   has a line to spare and putting a sentence beside the control instead
205//!   would push every option's radio out of line with its neighbours.
206//!
207//! The value still arrives as a `&mut String` and a slider is a number, so the
208//! parse and the write-back are this renderer's, and the write happens only on
209//! a real drag: a value the app put there that this host cannot read survives
210//! being looked at.
211
212#![forbid(unsafe_code)]
213
214use egui::{
215    Color32, ComboBox, CornerRadius, DragValue, Margin, Painter, Rect, Response, RichText, Shape,
216    Slider, Stroke, TextEdit, Ui,
217};
218use makeover_layout::{
219    Bevel, Choice, Depth, Edge, Field, FieldKind, Fill, State, ThemeVariant, Tone,
220};
221use std::ops::RangeInclusive;
222
223/// Columns, narrowing, cell parts and the sort caret, over `egui_extras`.
224pub mod host;
225pub mod table;
226pub mod widget;
227
228/// The resolved colours this renderer needs, as flat values.
229///
230/// Built by the app from whatever it already uses to resolve a theme, then
231/// held and reused. Deliberately not a trait and not string-keyed: a bevel is
232/// painted per widget per frame, and a map lookup per edge is a cost with
233/// nothing to show for it.
234#[derive(Debug, Clone, Copy, PartialEq, Eq)]
235pub struct Palette {
236    /// `surface-page`.
237    pub page: Color32,
238    /// `surface-raised`.
239    pub raised: Color32,
240    /// `surface-overlay`.
241    pub overlay: Color32,
242    /// `surface-well`.
243    ///
244    /// Required, not optional. makeover derives it for every theme, so a
245    /// resolved palette without a well is not a thing that exists here.
246    /// `makeover-tui` keeps its own `Option` for a different reason, since a
247    /// terminal can have the colour and still be unable to show it.
248    pub well: Color32,
249    /// `surface-sunken`.
250    ///
251    /// A surface set back from the one it sits on, by colour and nothing else.
252    /// Not a well: a well is a hole with an edge, and this has no edge. An
253    /// immediate-mode renderer paints an arbitrary rect, so unlike
254    /// `makeover-tui` it has no excuse for declining this one.
255    ///
256    /// Required rather than optional, on the same footing as `well`: all 31
257    /// themes makeover embeds author it.
258    pub sunken: Color32,
259    /// `bevel-light`.
260    pub bevel_light: Color32,
261    /// `bevel-dark`.
262    pub bevel_dark: Color32,
263    /// `elevation`.
264    ///
265    /// What a surface that floats OVER the page is cast onto it with. The one
266    /// intent here that is about a surface's relationship to the page rather
267    /// than about the surface, which is why it is a translucent near-black on
268    /// every theme rather than something read off the palette's own ramp.
269    ///
270    /// **Only for a surface that overlays.** A menu, a tooltip, a modal. A
271    /// surface *in* the layout takes a bevel, and reaching for this on a panel
272    /// or a card is how a pre-Platinum look survives a conversion under a new
273    /// name.
274    ///
275    /// egui has a real answer for this where a terminal does not: see
276    /// [`Palette::cast`], which is the shadow to hand an
277    /// [`egui::Frame`](egui::Frame).
278    pub elevation: Color32,
279    /// `content`.
280    ///
281    /// Ordinary text.
282    pub content: Color32,
283    /// `content-secondary`.
284    ///
285    /// Inactive but usable: it still answers a press. The middle tone of the
286    /// three (wiki `three-tone-convention`), and the one an unchosen option in
287    /// a choice field takes.
288    ///
289    /// Not [`content_muted`](Self::content_muted), which carries a claim:
290    /// `State::Disabled` resolves to it, so a live control wearing it tells the
291    /// user it will not answer. `makeover-tui` draws the same widget the same
292    /// way from `makeover-tui@230bf63`.
293    ///
294    /// A step of `content` toward the page, derived at load by `makeover`
295    /// rather than authored, so it is read off the resolved theme here like
296    /// any other token and never re-derived.
297    pub content_secondary: Color32,
298    /// `content-muted`.
299    ///
300    /// A field's hint, and what
301    /// [`makeover_layout::State::Disabled`](makeover_layout::State::Disabled)
302    /// resolves to. Both readings come from the description rather than from
303    /// here: `State::Disabled` names this intent by token.
304    pub content_muted: Color32,
305    /// `action-primary`.
306    ///
307    /// What a control is drawn in.
308    ///
309    /// This is the intent [`CellPart`](makeover_layout::CellPart) exists to
310    /// separate. A cell holding a control that takes the cell's text colour is
311    /// the drift `CellPart` names.
312    pub action: Color32,
313    /// `danger`.
314    ///
315    /// A field's error message, a destructive control, a bar that has run over.
316    pub danger: Color32,
317    /// `success`.
318    ///
319    /// The three status intents arrive together and not one at a time:
320    /// [`Tone`] is five members wide and a resolver missing one has to invent
321    /// a colour for it, which is the substitution [`Palette::fill`] refuses.
322    pub success: Color32,
323    /// `warning`.
324    pub warning: Color32,
325    /// `info`.
326    pub info: Color32,
327    /// `border`, the authored line colour.
328    ///
329    /// A neutral badge's edge: a badge on the raised ground is raised too, so
330    /// the edge is what draws it.
331    pub border: Color32,
332    /// `info-surface`: raised with 12 percent of `info`. A badge's fill.
333    ///
334    /// The four tone surfaces arrive together for the status intents' reason.
335    pub info_surface: Color32,
336    /// `success-surface`.
337    pub success_surface: Color32,
338    /// `warning-surface`.
339    pub warning_surface: Color32,
340    /// `danger-surface`.
341    pub danger_surface: Color32,
342    /// `row-stripe`: every second row of a table, ink mixed into raised at 5
343    /// percent (wiki `table-model`).
344    pub row_stripe: Color32,
345    /// `row-hover`: the row under the pointer, at 9 percent.
346    pub row_hover: Color32,
347    /// `row-rule`: the hairline between rows and around a table, at 26
348    /// percent.
349    pub row_rule: Color32,
350    /// `row-selected`: a selected row, raised with 18 percent of the accent.
351    ///
352    /// A fill and never a foreground, so a row that is red for a failure stays
353    /// red while it is selected.
354    pub row_selected: Color32,
355}
356
357impl Palette {
358    /// Resolve a surface intent, or `None` for one this renderer does not know.
359    ///
360    /// A plain lookup, and no substitution.
361    ///
362    /// `Option`, because [`Fill`] is `#[non_exhaustive]` and a total function
363    /// over an open enum can only stay total by inventing a colour for a member
364    /// it has never heard of. Every member the description has today is
365    /// answered with `Some`.
366    #[must_use]
367    pub const fn fill(&self, fill: Fill) -> Option<Color32> {
368        match fill {
369            Fill::Page => Some(self.page),
370            Fill::Raised => Some(self.raised),
371            Fill::Overlay => Some(self.overlay),
372            Fill::Well => Some(self.well),
373            Fill::Sunken => Some(self.sunken),
374            _ => None,
375        }
376    }
377
378    /// The colour a [`Tone`] reads as.
379    ///
380    /// Total, unlike [`fill`](Self::fill), and the difference is not an
381    /// inconsistency. `Fill` is `#[non_exhaustive]` and `Tone` is not: the
382    /// description layer settled tone at five members and grows surfaces, so a
383    /// total function here cannot be made to invent a colour by an upstream
384    /// release the way a total `fill` could.
385    ///
386    /// [`Tone::Neutral`] is [`content`](Self::content) rather than a colour of
387    /// its own, which is what "an ordinary fact" means: a neutral badge is text
388    /// in a box, not a fifth status.
389    #[must_use]
390    pub const fn tone(&self, tone: Tone) -> Color32 {
391        match tone {
392            Tone::Neutral => self.content,
393            Tone::Info => self.info,
394            Tone::Success => self.success,
395            Tone::Warning => self.warning,
396            Tone::Danger => self.danger,
397        }
398    }
399
400    /// What a badge of this tone is filled with: its tone surface, or the
401    /// raised surface for [`Tone::Neutral`], as `makeover-webview` fills one.
402    #[must_use]
403    pub const fn tone_surface(&self, tone: Tone) -> Color32 {
404        match tone {
405            Tone::Neutral => self.raised,
406            Tone::Info => self.info_surface,
407            Tone::Success => self.success_surface,
408            Tone::Warning => self.warning_surface,
409            Tone::Danger => self.danger_surface,
410        }
411    }
412
413    /// What a badge of this tone is edged with: its tone, or
414    /// [`border`](Self::border) for [`Tone::Neutral`], whose tone is the ink.
415    #[must_use]
416    pub const fn tone_edge(&self, tone: Tone) -> Color32 {
417        match tone {
418            Tone::Neutral => self.border,
419            other => self.tone(other),
420        }
421    }
422
423    /// The cast shadow for a surface that overlays the page.
424    ///
425    /// What "overlaying" means in immediate mode, answered rather than skipped.
426    /// egui already paints shadows for its menus and windows through
427    /// [`egui::Frame::shadow`], so the honest port is to hand that machinery the
428    /// theme's tone instead of egui's own default, not to invent a painter here
429    /// the way [`paint_bevel`] had to.
430    ///
431    /// The geometry matches what `makeover-webview` composes, in points rather
432    /// than pixels: a small downward offset and a wide soft blur. A Platinum-era
433    /// menu sits just off the page rather than hovering above it.
434    ///
435    /// ```no_run
436    /// # let palette: makeover_immediate::Palette = unimplemented!();
437    /// # let ui: &mut egui::Ui = unimplemented!();
438    /// egui::Frame::popup(ui.style())
439    ///     .shadow(palette.cast())
440    ///     .show(ui, |ui| { ui.label("over the page"); });
441    /// ```
442    #[must_use]
443    pub const fn cast(&self) -> egui::Shadow {
444        egui::Shadow {
445            offset: [0, 2],
446            blur: 24,
447            spread: 0,
448            color: self.elevation,
449        }
450    }
451
452    /// Resolve a bevel edge intent.
453    #[must_use]
454    pub const fn edge(&self, edge: Edge) -> Color32 {
455        match edge {
456            Edge::Light => self.bevel_light,
457            Edge::Dark => self.bevel_dark,
458        }
459    }
460}
461
462/// The geometry a framed region is drawn with.
463///
464/// Every field is a value, which is why they all arrive from the caller:
465/// radius and border width belong to `makeover-geometry`, and margins come
466/// from its relational gaps.
467#[derive(Debug, Clone, Copy, PartialEq)]
468pub struct FrameStyle {
469    /// Corner radius. Square under the Platinum default.
470    pub radius: CornerRadius,
471    /// Inner margin between the frame and its contents.
472    pub margin: Margin,
473    /// Bevel stroke width, in points.
474    pub stroke: f32,
475}
476
477impl Default for FrameStyle {
478    /// A one-point square frame with no inner margin.
479    fn default() -> Self {
480        Self {
481            radius: CornerRadius::ZERO,
482            margin: Margin::ZERO,
483            stroke: 1.0,
484        }
485    }
486}
487
488/// Paint a two-tone edge just inside `rect`.
489///
490/// Fill first, bevel after: this adds two polylines and nothing else, so it
491/// composes over whatever is already there. That is what lets it go over an
492/// [`egui::TextEdit`] after `ui.add`, where the widget's own fill has landed.
493///
494/// Two three-point polylines meeting at opposite corners, rather than four
495/// segments, so egui mitres the corner joins instead of leaving a notch.
496///
497/// The dark polyline is drawn second, so the two corners where the runs meet
498/// take its tone. That is the right answer here rather than a concession.
499/// [`makeover_layout::Bevel`] holds those corners to belong to both edges, and
500/// a renderer with room to divide one should; at the default one-point stroke
501/// the corner is a one-point square, so the division is sub-pixel and
502/// antialiasing resolves it to the same blend the mitre already gives. Splitting
503/// it would add a seam and no information. `makeover-tui` does split, because a
504/// terminal cell is large enough that not splitting costs a visible cell of edge
505/// weight — the same rule, at a resolution where it has something to say.
506pub fn paint_bevel(painter: &Painter, rect: Rect, bevel: Bevel, palette: &Palette, stroke: f32) {
507    let (top_left, bottom_right) = bevel.edges();
508
509    // Inset by half a stroke so the line lands inside `rect` rather than
510    // straddling its edge, which on a fractional-scale display is the
511    // difference between one crisp pixel and two dim ones.
512    let r = rect.shrink(stroke / 2.0);
513
514    painter.add(Shape::line(
515        vec![r.left_bottom(), r.left_top(), r.right_top()],
516        Stroke::new(stroke, palette.edge(top_left)),
517    ));
518    // Three points close the box, two leave the bottom open: the shaded run
519    // comes down the right side and stops. That is the folder tab, and it is
520    // the same edge the browser draws by dropping the shadow's vertical
521    // offset. The lit polyline is untouched either way, so the join is the
522    // only thing that changes.
523    let shaded = if bevel.draws_bottom() {
524        vec![r.right_top(), r.right_bottom(), r.left_bottom()]
525    } else {
526        vec![r.right_top(), r.right_bottom()]
527    };
528    painter.add(Shape::line(
529        shaded,
530        Stroke::new(stroke, palette.edge(bottom_right)),
531    ));
532}
533
534/// Draw a region at a given [`Depth`]: its fill and its edge, together.
535///
536/// [`Depth::Flat`] gets neither, and inherits whatever it sits on. That is the
537/// difference between level-with and painted-the-same-colour, and it is the
538/// reason `Depth::fill` returns an [`Option`] rather than defaulting to the
539/// page.
540pub fn frame<R>(
541    ui: &mut Ui,
542    depth: Depth,
543    palette: &Palette,
544    style: FrameStyle,
545    add_contents: impl FnOnce(&mut Ui) -> R,
546) -> R {
547    let mut f = egui::Frame::new()
548        .corner_radius(style.radius)
549        .inner_margin(style.margin);
550    // Two ways there is no fill to paint, and they collapse to the same
551    // outcome: the depth names none (Depth::Flat), or it names one this
552    // renderer cannot resolve. Either way the frame goes unfilled and the
553    // bevel below carries the depth on its own, which is the rule this
554    // module already documents for Flat.
555    if let Some(fill) = depth.fill().and_then(|f| palette.fill(f)) {
556        f = f.fill(fill);
557    }
558    // A surface that overlays the page is cast onto it. [`Palette::cast`] has
559    // answered what that means here since 0.10.0 and nothing could reach it: a
560    // description had no way to say Overlay until makeover-layout 0.14.0, so
561    // the answer sat beside the question. Keyed off the fill rather than the
562    // variant, so it stays right for whatever else the description calls an
563    // overlay later.
564    if depth.fill() == Some(Fill::Overlay) {
565        f = f.shadow(palette.cast());
566    }
567    let framed = f.show(ui, add_contents);
568    if let Some(bevel) = depth.bevel() {
569        paint_bevel(
570            ui.painter(),
571            framed.response.rect,
572            bevel,
573            palette,
574            style.stroke,
575        );
576    }
577    framed.inner
578}
579
580/// The geometry a field group is drawn with.
581///
582/// Values again, for the reason [`FrameStyle`] is: every number here belongs to
583/// `makeover-geometry` and arrives already resolved.
584#[derive(Debug, Clone, Copy, PartialEq)]
585pub struct FieldStyle {
586    /// The well a text control sits in.
587    pub frame: FrameStyle,
588    /// Between a field's own parts: its label, its control, its hint and its
589    /// error.
590    pub gap: f32,
591    /// Between one field and the next.
592    pub group_gap: f32,
593    /// What marks a required field, appended to its label.
594    ///
595    /// A knob rather than a constant, because it is the one piece of *copy* in
596    /// this crate and copy is not a renderer's call. A webview does not need it
597    /// at all — it emits the `required` attribute and the browser answers — so
598    /// this renderer is the first place where a compulsory field either shows
599    /// that it is or silently does not.
600    pub required_marker: &'static str,
601}
602
603impl Default for FieldStyle {
604    /// The default frame, no gaps, and an asterisk.
605    fn default() -> Self {
606        Self {
607            frame: FrameStyle::default(),
608            gap: 0.0,
609            group_gap: 0.0,
610            required_marker: "*",
611        }
612    }
613}
614
615/// What the field currently holds, borrowed from wherever the app keeps it.
616///
617/// The immediate-mode counterpart of `makeover_webview::form::Value`, and the
618/// place the two renderers are forced apart: there the value is read back out
619/// of the DOM after the fact, and here the widget writes through this borrow as
620/// it is edited. Same reason the description carries neither.
621///
622/// An enum rather than a bag of options, on the reasoning
623/// `makeover_webview::form::Value` records: a checkbox holding a string is
624/// unsayable here, where a struct would let it be said and then have to cope.
625///
626/// `#[non_exhaustive]` since [`Ticked`](Self::Ticked) arrived, which is the
627/// breaking change that made room for it: a host builds these and never matches
628/// on them, so the next shape of held value costs nobody a match arm.
629#[derive(Debug, Default)]
630#[non_exhaustive]
631pub enum Filling<'a> {
632    /// Nothing to edit. The control is drawn and does not answer.
633    #[default]
634    Absent,
635    /// The buffer behind anything that takes typed text, a select included:
636    /// what a select holds is the `value` of one of its [`Choice`]s.
637    ///
638    /// [`Choice`]: makeover_layout::Choice
639    Text(&'a mut String),
640    /// A checkbox, on or off.
641    On(&'a mut bool),
642    /// The values of a [`FieldKind::Checklist`]'s ticked options.
643    ///
644    /// The values rather than a bool per option, because the options are the
645    /// description's and the set is the app's: a host keeps what was ticked
646    /// under the option values it submits, and a parallel list of bools would
647    /// have to be re-aligned with the options every time the list changed.
648    /// Ticking pushes the option's value and unticking removes it, so the order
649    /// is the order things were ticked in, which is no order a handler should
650    /// read anything into.
651    Ticked(&'a mut Vec<String>),
652    /// The two buffers behind a [`FieldKind::Interval`], lower first.
653    ///
654    /// Two buffers rather than one string with a separator, which is
655    /// [`makeover_layout::Field::upper_name`]'s reason one level down: an
656    /// interval is submitted under two names, so it is edited as two values,
657    /// and a delimiter this crate owned could appear inside either of them.
658    ///
659    /// Either end may be empty while the other stands. An open end is an
660    /// answer -- "over 120 BPM" -- rather than a half-filled box.
661    Between {
662        /// The lower end's buffer.
663        lower: &'a mut String,
664        /// The upper end's buffer.
665        upper: &'a mut String,
666    },
667}
668
669/// The label, marked if the field is compulsory.
670fn label_text(field: &Field<'_>, style: &FieldStyle) -> String {
671    if field.required {
672        format!("{} {}", field.label, style.required_marker)
673    } else {
674        field.label.to_owned()
675    }
676}
677
678/// The four shapes a control comes in here, which is fewer than there are
679/// kinds.
680///
681/// [`FieldKind`] is `#[non_exhaustive]` and grows; this does not, because the
682/// ways egui has of asking for a value do not. Reducing the open set to this
683/// closed one in one total function is what keeps a new kind from needing a new
684/// arm at every match below.
685#[derive(Debug, Clone, Copy, PartialEq, Eq)]
686enum Control {
687    /// Typed into, so it is drawn as a well: the user looks into it.
688    Typed,
689    /// Picked from a control that shows one option at a time. Pressed rather
690    /// than looked into, so egui's own control painting stands.
691    Chosen,
692    /// Picked from options that are all on screen at once.
693    ///
694    /// Apart from [`Chosen`](Self::Chosen) because the description holds them
695    /// apart, and holding them apart is the whole content of
696    /// [`FieldKind::Radio`]: same question, and an answer the user can read
697    /// without opening anything.
698    Listed,
699    /// Ticked from options that are all on screen at once, as many as apply.
700    ///
701    /// Apart from [`Listed`](Self::Listed) because picking one leaves the
702    /// others standing, and apart from [`Toggled`](Self::Toggled) because it is
703    /// one question: [`FieldKind::Checklist`] asks it above its boxes, where a
704    /// checkbox is its own label.
705    Ticked,
706    /// Held on or off.
707    Toggled,
708    /// Dragged across an extent that is on screen the whole time.
709    ///
710    /// Apart from [`Typed`](Self::Typed) for the reason
711    /// [`FieldKind::Range`] is apart from `Number`: the two ends are what the
712    /// question means, so a well with a figure in it is not a quieter version
713    /// of this control, it is a different one.
714    Slid,
715    /// Picked from a list of themes that arrives grouped and marked.
716    ///
717    /// Apart from [`Chosen`](Self::Chosen) rather than folded into it, and the
718    /// distinction is the same one [`Listed`](Self::Listed) draws: it is not a
719    /// different question, it is a different amount of structure on screen. A
720    /// theme picker's rows carry a group heading and a contrast mark, and both
721    /// come from members [`Field::options`] does not have, so a shared arm
722    /// would be a `matches!` on the kind inside the loop rather than one arm
723    /// less.
724    Themed,
725    /// Two values dragged across one axis, drawn as one question.
726    ///
727    /// Apart from [`Typed`](Self::Typed) for the reason
728    /// [`FieldKind::Interval`] is apart from `Number`: two wells one under the
729    /// other are two questions on screen, whatever the description says, and
730    /// the arrangement is the whole content of the kind.
731    Spanned,
732}
733
734/// Which shape a kind takes.
735///
736/// The wildcard falls to [`Control::Typed`] on purpose: a kind added to the
737/// description since this renderer was built degrades to a text box, which
738/// accepts any value the others would, rather than to nothing drawn at all.
739///
740/// `FieldKind::File` lands there rather than growing a shape of its own. egui's
741/// honest answer is a button that opens a native picker, which is a fifth
742/// control and a file-dialog dependency, and no consumer of this crate asks for
743/// a file field. The membership test is that every renderer *could* answer
744/// honestly, not that each one does on the day. A path in a text box is not
745/// nothing.
746///
747/// `Field::accept` and `Field::multiple` land on the same position: both are the picker's arguments, and this
748/// renderer has no picker to give them to. They are not lost — the description
749/// still carries them, and the day the native dialog arrives here it is opened
750/// with them rather than with a filter written twice.
751///
752/// `FieldKind::Date` and `FieldKind::DateTime` land there too, on the same
753/// footing and with one thing owed. A
754/// calendar is a sixth control and bare `egui` has none, so a typed value is
755/// the honest answer here; what the app gets is the format the description
756/// names, `makeover_layout::DATE_FORMAT` and `DATETIME_FORMAT`, which is why
757/// those are constants rather than a sentence. audiofiles is the only consumer
758/// of this crate and asks for neither today. A calendar popup is the upgrade
759/// whenever one does.
760///
761/// `Field::as_instant` is carried and not honoured, on
762/// the same footing. It asks for the typed wall-clock value to be submitted as
763/// the moment it names, and this renderer has no submission to convert on: it
764/// draws the control and the app reads the value back, so the conversion would
765/// belong wherever that read happens rather than here. What the app gets is the
766/// local value in `DATETIME_FORMAT`, which is what it got before the member
767/// existed. No described site on this host asks for it today.
768/// One row of a closed chooser, as the single string it has room for.
769///
770/// A combo hides its list, so everything an option carries has to travel with
771/// the row it belongs to: there is no second line to put a detail on and no
772/// space beside the row to put a reason in. That is the same constraint a
773/// `<select>`'s option has in the webview, and it takes the same answer.
774///
775/// The order is what the option *is* before why it cannot be picked, which is
776/// the order the two read in and the order the radio group draws them in.
777fn combo_row(opt: &Choice<'_>) -> String {
778    let mut text = opt.label.to_owned();
779    for extra in [opt.detail, opt.unavailable].into_iter().flatten() {
780        text.push_str("  ");
781        text.push_str(extra);
782    }
783    text
784}
785
786/// How far an option's second line is inset, in points.
787///
788/// The width of egui's radio button plus the gap after it, so the line starts under the label rather than under the control. A
789/// magnitude, which is `makeover-geometry`'s subject and not this crate's --
790/// but this one is measured off a widget egui draws and sizes, so there is
791/// nothing for a spacing scale to say about it.
792const OPTION_DETAIL_INDENT: f32 = 22.0;
793
794const fn control_shape(kind: FieldKind) -> Control {
795    match kind {
796        FieldKind::Select => Control::Chosen,
797        FieldKind::Radio => Control::Listed,
798        FieldKind::Checklist => Control::Ticked,
799        FieldKind::Checkbox => Control::Toggled,
800        FieldKind::Range => Control::Slid,
801        FieldKind::Interval => Control::Spanned,
802        FieldKind::Theme => Control::Themed,
803        _ => Control::Typed,
804    }
805}
806
807/// The shape the field actually gets, which is the kind's unless the field is
808/// missing what that shape needs.
809///
810/// One case, and `makeover-layout` names it: a [`FieldKind::Range`] carries its
811/// extent in [`Field::min`] and [`Field::max`], and a range missing an end has
812/// nothing to slide across. egui's `Slider` demands a `RangeInclusive`, so
813/// inventing one would be this renderer picking bounds the app never stated and
814/// the user then dragging against them.
815///
816/// It falls back to [`Control::Typed`], which is where every kind this renderer
817/// cannot draw natively already lands: a number in a well is a true report of
818/// the value and takes any answer the slider would.
819fn shape_of(field: &Field<'_>) -> Control {
820    match control_shape(field.kind) {
821        Control::Slid if !field.bounded() => Control::Typed,
822        shape => shape,
823    }
824}
825
826/// The unit to draw beside this field's value, if there is one to draw.
827///
828/// Two conditions rather than one: the field has to carry a unit and its kind
829/// has to be one that means anything by it. `FieldKind::measurable` is the
830/// description answering the second, so this renderer does not keep its own
831/// list of which kinds are quantities -- which is the drift that predicate
832/// exists to stop.
833fn unit_of<'a>(field: &Field<'a>) -> Option<&'a str> {
834    field.unit.filter(|_| field.kind.measurable())
835}
836
837/// The two ends of a range, as egui wants them.
838///
839/// `None` when either end is missing or is not a number this host can read.
840/// The description carries the bounds as text on purpose — the bound of a date
841/// is a date — so parsing them is the renderer's job and failing to is a real
842/// outcome rather than an assertion.
843fn extent(field: &Field<'_>) -> Option<RangeInclusive<f64>> {
844    let min = field.min?.parse::<f64>().ok()?;
845    let max = field.max?.parse::<f64>().ok()?;
846    Some(min..=max)
847}
848
849/// How many decimals to write a dragged value back with.
850///
851/// Read off [`Field::step`], which is the only thing that says what
852/// granularity the question has: a step of `0.01` is a two-decimal question and
853/// a step of `1` is a whole-number one. Without a step the host's own
854/// granularity stands, and egui's is continuous, so the value is written back
855/// at whatever precision it round-trips at.
856fn decimals(step: Option<&str>) -> Option<usize> {
857    let step = step?;
858    Some(match step.split_once('.') {
859        Some((_, fraction)) => fraction.trim_end_matches('0').len(),
860        None => 0,
861    })
862}
863
864/// What a select shows for the value it currently holds.
865///
866/// A value no option carries stays on screen as itself rather than reading as
867/// whichever option happens to be first. goingson saved a backup retention of
868/// 10 against a 1/3/7/14/0 list and the browser silently showed it as 1, so the
869/// next save wrote a value nobody chose; `makeover-webview` grew the fix as a
870/// stray `<option>` and this is the same fix in the shape egui allows.
871///
872/// The empty value is the one case that reads as unanswered rather than as an
873/// answer, and [`chosen_text`] is what puts the field's ghost text there.
874fn shown_label<'a>(options: &'a [Choice<'a>], value: &'a str) -> &'a str {
875    options
876        .iter()
877        .find(|opt| opt.value == value)
878        .map_or(value, |opt| opt.label)
879}
880
881/// What a select's closed control reads, and in which tone.
882///
883/// A chooser with nothing chosen showed an empty box: `shown_label` falls back
884/// to the value, and the unanswered value is the empty string. So an app with
885/// an instruction to give — audiofiles' "Select device..." — had nowhere to put
886/// it but a disabled button elsewhere on the screen, which is the affordance
887/// this vocabulary keeps moving messages *off*.
888///
889/// [`Field::placeholder`] is already the description's word for "what the field
890/// reads while it is empty" and was honoured by the typed kinds alone, so
891/// nothing new is said here; the renderer is what had not caught up. Muted
892/// because it is not an answer, the same tone the typed kinds' ghost text takes
893/// three lines up.
894///
895/// A value no option carries but that is *not* empty stays as itself, in
896/// `content`: that is the goingson retention bug and it is a wrong answer
897/// rather than an absent one.
898///
899/// Returns the words and the tone rather than a built [`RichText`], because
900/// what it decides is both of them and only one of them is readable back off a
901/// `RichText`.
902///
903/// [`Field::placeholder`]: makeover_layout::Field::placeholder
904fn chosen_text<'a>(field: &'a Field<'a>, value: &'a str, palette: &Palette) -> (&'a str, Color32) {
905    match field.placeholder {
906        Some(ghost) if value.is_empty() => (ghost, palette.content_muted),
907        _ => (shown_label(field.options, value), palette.content),
908    }
909}
910
911/// What one option in a choice field is drawn in.
912///
913/// The chosen one is the emphasised thing and takes `content`; the rest take
914/// [`content_secondary`](Palette::content_secondary), because an option that is
915/// not chosen is still an option and pressing it chooses it. Muted would be the
916/// lie: [`State::Disabled`] resolves to it, so a five-option field read as one
917/// live row and four dead ones. `makeover-tui` draws it the same way
918/// (`makeover-tui@230bf63`); wiki `three-tone-convention` is the table.
919fn option_color(value: &str, option: &str, palette: &Palette) -> Color32 {
920    if value == option {
921        palette.content
922    } else {
923        palette.content_secondary
924    }
925}
926
927/// Which end of an interval a box is.
928///
929/// Named rather than a bool, because what it selects is not a side but a
930/// fallback: an empty end reads as the bound it stands for, and which bound
931/// that is depends on the end.
932#[derive(Debug, Clone, Copy, PartialEq, Eq)]
933enum Bound {
934    /// The lower end, falling back to the start of the extent.
935    Low,
936    /// The upper end, falling back to its end.
937    High,
938}
939
940/// The facts an interval's two boxes share.
941///
942/// One struct because they are one axis: [`Field::min`], [`Field::max`],
943/// [`Field::step`] and [`Field::unit`] describe the question rather than either
944/// end of it, so reading them once is what stops the two boxes drifting apart.
945struct Axis<'a> {
946    /// The extent both ends are dragged inside, when it is one this host can
947    /// read.
948    extent: Option<RangeInclusive<f64>>,
949    /// The granularity, as the description writes it.
950    step: Option<&'a str>,
951    /// What the axis is measured in.
952    unit: Option<&'a str>,
953}
954
955impl Axis<'_> {
956    /// What an empty end reads as: the bound it stands for.
957    ///
958    /// Zero with no extent to fall back on. That is the one number this
959    /// renderer invents, and it invents it where the description declined to
960    /// say anything: an unbounded interval has no edge for the end to sit on,
961    /// and a drag box has to start somewhere.
962    fn edge(&self, which: Bound) -> f64 {
963        self.extent.as_ref().map_or(0.0, |extent| match which {
964            Bound::Low => *extent.start(),
965            Bound::High => *extent.end(),
966        })
967    }
968
969    /// One end of the interval, as a drag box.
970    ///
971    /// # An empty end reads as its bound
972    ///
973    /// Which is what the shipped control did before it was described: an unset
974    /// minimum sits on the low edge and stores no filter. egui's `DragValue`
975    /// holds a number and has no empty state to offer, so the alternative was a
976    /// text box, and that would cost the app a control on the way into being
977    /// described.
978    ///
979    /// With no extent to fall back on, an empty end reads zero. That is the one
980    /// number this renderer invents, and it invents it where the description
981    /// declined to say anything: an unbounded interval has no edge for the end
982    /// to sit on, and a drag box has to start somewhere.
983    ///
984    /// Nothing is written back until the user drags, so a value the app put
985    /// there survives being looked at -- the same guarantee the slider makes.
986    fn end(&self, ui: &mut Ui, value: &mut String, which: Bound) -> Response {
987        let mut number = value.parse::<f64>().unwrap_or(self.edge(which));
988        let mut drag = DragValue::new(&mut number);
989        if let Some(extent) = self.extent.clone() {
990            drag = drag.range(extent);
991        }
992        if let Some(places) = decimals(self.step) {
993            drag = drag.max_decimals(places);
994        }
995        if let Some(step) = self.step.and_then(|s| s.parse::<f64>().ok()) {
996            drag = drag.speed(step);
997        }
998        // Inside the control, beside the readout, which is where `Field::unit`
999        // was decided to belong and where these boxes already put it.
1000        if let Some(unit) = self.unit {
1001            drag = drag.suffix(format!(" {unit}"));
1002        }
1003        let response = ui.add(drag);
1004        if response.changed() {
1005            *value = match decimals(self.step) {
1006                Some(places) => format!("{number:.places$}"),
1007                None => number.to_string(),
1008            };
1009        }
1010        response
1011    }
1012}
1013
1014/// The control alone, without its label, hint or error.
1015fn control(
1016    ui: &mut Ui,
1017    field: &Field<'_>,
1018    filling: Filling<'_>,
1019    palette: &Palette,
1020    style: &FieldStyle,
1021    named_by: Option<egui::Id>,
1022) -> Response {
1023    // The mismatch path: described as one thing and filled as another. Nothing
1024    // here can fix it, so it is drawn as the empty, inert version of what was
1025    // described — visible on screen, in the way an empty select is at the
1026    // webview renderer, rather than reported in a log nobody reads.
1027    let mut discard = String::new();
1028    // The interval's second scratch buffer. Two ends means the mismatch path
1029    // needs two places to write nothing to.
1030    let mut spare = String::new();
1031    let mut off = false;
1032
1033    match shape_of(field) {
1034        Control::Slid => {
1035            let value = match filling {
1036                Filling::Text(text) => text,
1037                _ => &mut discard,
1038            };
1039            // `shape_of` has already refused an unbounded range, so the extent
1040            // is only missing here if a bound is not a number — a date range,
1041            // say, which this control cannot draw either.
1042            let Some(extent) = extent(field) else {
1043                return ui.label(RichText::new(value.as_str()).color(palette.content));
1044            };
1045
1046            // A value the host cannot read starts at the low end rather than at
1047            // zero, which may be outside the extent entirely. Nothing is
1048            // written back until the user drags, so an unreadable value the app
1049            // put there survives being looked at.
1050            let mut number = value.parse::<f64>().unwrap_or(*extent.start());
1051            // The granularity is the curve's as of makeover-layout 0.32.0. It
1052            // is still in the value's own units, so the display precision is
1053            // read off it exactly as before.
1054            let step = field.curve.step();
1055            let mut slider = Slider::new(&mut number, extent.clone()).text("");
1056            if let Some(places) = decimals(step) {
1057                slider = slider.max_decimals(places);
1058            }
1059            if let Some(step) = step.and_then(|s| s.parse::<f64>().ok()) {
1060                slider = slider.step_by(step);
1061            }
1062            // egui's own constant-ratio track, which is this host's answer to
1063            // `Curve::Logarithmic`. `is_ratio` rather than a match on the
1064            // variant, because a ratio across zero is not one: makeover-layout
1065            // decides the fallback so that four renderers cannot disagree about
1066            // when it applies.
1067            if field.curve.is_ratio(*extent.start(), *extent.end()) {
1068                slider = slider.logarithmic(true);
1069            }
1070            // The unit goes inside the control, beside the readout egui already
1071            // draws. That placement is the argument `Field::unit` was decided
1072            // on: it is where these controls put it before they were described,
1073            // and it is the one a label could never reach.
1074            if let Some(unit) = unit_of(field) {
1075                slider = slider.suffix(format!(" {unit}"));
1076            }
1077            let response = ui.add(slider);
1078            if response.changed() {
1079                *value = match decimals(step) {
1080                    Some(places) => format!("{number:.places$}"),
1081                    None => number.to_string(),
1082                };
1083            }
1084            response
1085        }
1086        // One question, so one row. Two wells stacked would be two questions on
1087        // screen whatever the description said, which is the reading
1088        // `FieldKind::Interval` exists to prevent.
1089        //
1090        // Dragged rather than typed, because that is what these controls
1091        // already were: audiofiles' six filter axes are `DragValue` pairs with
1092        // a shared extent, a speed and a suffix, and a port that turned them
1093        // into text boxes would be a description costing the app a control.
1094        Control::Spanned => {
1095            let (lower, upper) = match filling {
1096                Filling::Between { lower, upper } => (lower, upper),
1097                _ => (&mut discard, &mut spare),
1098            };
1099            let axis = Axis {
1100                extent: extent(field),
1101                step: field.step,
1102                unit: unit_of(field),
1103            };
1104            ui.horizontal(|ui| {
1105                let low = axis.end(ui, lower, Bound::Low);
1106                // The word rather than a dash. A dash between two numbers is a
1107                // minus sign on a signed axis, and audiofiles filters loudness
1108                // in dBFS.
1109                ui.label(RichText::new("to").color(palette.content_secondary));
1110                let high = axis.end(ui, upper, Bound::High);
1111                // Both ends, by name. A union response carries the first id, so
1112                // labelling the union outside this arm names the lower box and
1113                // leaves the upper one announced as whatever number is in it --
1114                // which is how an interval half-kept the fix that gave every
1115                // other shape its question.
1116                if let Some(id) = named_by {
1117                    low.clone().labelled_by(id);
1118                    high.clone().labelled_by(id);
1119                }
1120                low | high
1121            })
1122            .inner
1123        }
1124        Control::Typed => {
1125            let text = match filling {
1126                Filling::Text(text) => text,
1127                _ => &mut discard,
1128            };
1129            // An empty frame and no margin: the well is this crate's, and egui's
1130            // own control background and padding would sit underneath it saying
1131            // something different about both.
1132            // Keyed on the description's own `multiline` and not on the
1133            // member: a markdown field is several lines by definition, and a
1134            // single-line edit would be a control the value cannot fit in. egui
1135            // does nothing else with the markdown, which is the honest answer
1136            // rather than a gap -- the source is text, and editing it as text
1137            // loses none of it.
1138            let mut edit = if field.kind.multiline() {
1139                TextEdit::multiline(text)
1140            } else {
1141                TextEdit::singleline(text)
1142            }
1143            .frame(egui::Frame::NONE)
1144            .margin(Margin::ZERO)
1145            .text_color(palette.content)
1146            .password(field.kind.confidential());
1147            if let Some(ghost) = field.placeholder {
1148                edit = edit.hint_text(RichText::new(ghost).color(palette.content_muted));
1149            }
1150            let response = frame(ui, Depth::Well, palette, style.frame, |ui| ui.add(edit));
1151            // A typed number has no readout of its own to sit beside, so the
1152            // unit follows the box. Muted, because it is a fact about the value
1153            // rather than a second thing to read.
1154            match unit_of(field) {
1155                Some(unit) => {
1156                    ui.label(RichText::new(unit).color(palette.content_muted));
1157                    response
1158                }
1159                None => response,
1160            }
1161        }
1162        Control::Toggled => {
1163            let on = match filling {
1164                Filling::On(on) => on,
1165                _ => &mut off,
1166            };
1167            ui.checkbox(on, RichText::new(field.label).color(palette.content))
1168        }
1169        Control::Listed => {
1170            let value = match filling {
1171                Filling::Text(text) => text,
1172                _ => &mut discard,
1173            };
1174            // No `shown_label` counterpart, and none is needed: a value no
1175            // option carries leaves every button unfilled, which is already
1176            // the honest report on screen. The select needs the fix because it
1177            // has one slot and must put *something* in it.
1178            let group = ui.vertical(|ui| {
1179                let mut answered: Option<Response> = None;
1180                for opt in field.options {
1181                    // An option that cannot be picked yet is drawn and does not
1182                    // answer, with the precondition beside it rather than
1183                    // behind a hover: a greyed row with no reason reads as a
1184                    // dead end, which is the state `Choice::unavailable` exists
1185                    // to stop being sayable.
1186                    let picked = if let Some(reason) = opt.unavailable {
1187                        ui.horizontal(|ui| {
1188                            let picked = ui
1189                                .add_enabled_ui(false, |ui| {
1190                                    ui.radio_value(
1191                                        value,
1192                                        opt.value.to_owned(),
1193                                        RichText::new(opt.label).color(palette.content_muted),
1194                                    )
1195                                })
1196                                .inner;
1197                            ui.label(RichText::new(reason).color(palette.content_muted));
1198                            picked
1199                        })
1200                        .inner
1201                    } else {
1202                        ui.radio_value(
1203                            value,
1204                            opt.value.to_owned(),
1205                            RichText::new(opt.label).color(option_color(value, opt.value, palette)),
1206                        )
1207                    };
1208                    // What picking it means, under the option rather than
1209                    // beside it. makeover-layout 0.39.0, and the placement is
1210                    // the difference from the reason above: a precondition is
1211                    // short enough to sit on the line, and a sentence saying
1212                    // what a tier is would push every option's control out of
1213                    // line with its neighbours.
1214                    //
1215                    // Indented past the radio, so it reads as belonging to the
1216                    // option above rather than as a label of its own. Muted,
1217                    // the same reading `.form-option-detail` takes in the
1218                    // webview: the line orients the label, it does not compete
1219                    // with it.
1220                    if let Some(detail) = opt.detail {
1221                        ui.horizontal(|ui| {
1222                            ui.add_space(OPTION_DETAIL_INDENT);
1223                            ui.label(RichText::new(detail).color(palette.content_muted));
1224                        });
1225                    }
1226                    answered = Some(match answered {
1227                        Some(prev) => prev.union(picked),
1228                        None => picked,
1229                    });
1230                }
1231                answered
1232            });
1233            // A group described with no options answers as its own empty area
1234            // rather than as no response at all, which keeps the caller's
1235            // `.changed()` chain working on a field whose option list has not
1236            // loaded yet.
1237            group.inner.unwrap_or(group.response)
1238        }
1239        Control::Ticked => {
1240            // A host that lends no set still draws what the description
1241            // marked, which is `Choice::chosen` and the whole of what a
1242            // checklist carries about its answer.
1243            let mut seeded: Vec<String>;
1244            let ticked = if let Filling::Ticked(ticked) = filling {
1245                ticked
1246            } else {
1247                seeded = field
1248                    .options
1249                    .iter()
1250                    .filter(|opt| opt.chosen)
1251                    .map(|opt| opt.value.to_owned())
1252                    .collect();
1253                &mut seeded
1254            };
1255            let group = ui.vertical(|ui| {
1256                let mut answered: Option<Response> = None;
1257                for opt in field.options {
1258                    let mut on = ticked.iter().any(|value| value == opt.value);
1259                    let before = on;
1260                    // The radio group's rule for an option that cannot be
1261                    // picked yet: drawn, inert, and saying why on its own line.
1262                    let color = if !opt.available() {
1263                        palette.content_muted
1264                    } else if on {
1265                        palette.content
1266                    } else {
1267                        palette.content_secondary
1268                    };
1269                    let picked = ui
1270                        .horizontal(|ui| {
1271                            let picked = ui
1272                                .add_enabled_ui(opt.available(), |ui| {
1273                                    ui.checkbox(&mut on, RichText::new(opt.label).color(color))
1274                                })
1275                                .inner;
1276                            if let Some(reason) = opt.unavailable {
1277                                ui.label(RichText::new(reason).color(palette.content_muted));
1278                            }
1279                            picked
1280                        })
1281                        .inner;
1282                    if on != before {
1283                        if on {
1284                            ticked.push(opt.value.to_owned());
1285                        } else {
1286                            ticked.retain(|value| value != opt.value);
1287                        }
1288                    }
1289                    // Under the option, indented past the box, for the reason
1290                    // the radio group gives.
1291                    if let Some(detail) = opt.detail {
1292                        ui.horizontal(|ui| {
1293                            ui.add_space(OPTION_DETAIL_INDENT);
1294                            ui.label(RichText::new(detail).color(palette.content_muted));
1295                        });
1296                    }
1297                    answered = Some(match answered {
1298                        Some(prev) => prev.union(picked),
1299                        None => picked,
1300                    });
1301                }
1302                answered
1303            });
1304            group.inner.unwrap_or(group.response)
1305        }
1306        Control::Chosen => {
1307            let value = match filling {
1308                Filling::Text(text) => text,
1309                _ => &mut discard,
1310            };
1311            let (shown, tone) = chosen_text(field, value, palette);
1312            ComboBox::from_id_salt(field.name)
1313                .selected_text(RichText::new(shown).color(tone))
1314                .show_ui(ui, |ui| {
1315                    for opt in field.options {
1316                        // Same rule as the radio group: shown, inert, and
1317                        // saying why. A closed control hides its list, so the
1318                        // reason has to travel with the row it belongs to.
1319                        // A closed control hides its list, so everything an
1320                        // option carries has to travel with the row it belongs
1321                        // to. That is why both extra strings run into the text
1322                        // here and neither does in the group above: a combo
1323                        // row is a row, the way a `<select>`'s option is.
1324                        let text = combo_row(opt);
1325                        if opt.unavailable.is_some() {
1326                            ui.add_enabled_ui(false, |ui| {
1327                                ui.selectable_value(
1328                                    value,
1329                                    opt.value.to_owned(),
1330                                    RichText::new(text).color(palette.content_muted),
1331                                );
1332                            });
1333                            continue;
1334                        }
1335                        ui.selectable_value(
1336                            value,
1337                            opt.value.to_owned(),
1338                            RichText::new(text).color(option_color(value, opt.value, palette)),
1339                        );
1340                    }
1341                })
1342                .response
1343        }
1344        // The grouping comes out of the order rather than out of a group list:
1345        // `Field::themes` arrives sorted by variant, so the run of one variant
1346        // is the group and a heading opens whenever the variant changes. Same
1347        // walk as `makeover-webview`'s `<optgroup>` emission, which is what
1348        // keeps two renderers from disagreeing about where a group starts.
1349        Control::Themed => {
1350            let value = match filling {
1351                Filling::Text(text) => text,
1352                _ => &mut discard,
1353            };
1354            let shown = themed_text(field, value);
1355            ComboBox::from_id_salt(field.name)
1356                .selected_text(RichText::new(shown).color(palette.content))
1357                .show_ui(ui, |ui| {
1358                    if let Some(follow) = field.follows {
1359                        // First and outside every heading. It names no theme
1360                        // and sits in no variant, so a heading over it would be
1361                        // inventing a fourth variant for one row.
1362                        ui.selectable_value(
1363                            value,
1364                            follow.value.to_owned(),
1365                            RichText::new(follow.label).color(option_color(
1366                                value,
1367                                follow.value,
1368                                palette,
1369                            )),
1370                        );
1371                    }
1372                    let mut open: Option<ThemeVariant> = None;
1373                    for theme in field.themes {
1374                        if open != Some(theme.variant) {
1375                            // A heading rather than a `selectable_value`: it is
1376                            // not pickable, and egui has no inert row that
1377                            // still reads as a row. `content_muted` is the tone
1378                            // for something that is not an answer, which is the
1379                            // ghost text's tone eight lines up.
1380                            if open.is_some() {
1381                                ui.separator();
1382                            }
1383                            ui.label(
1384                                RichText::new(theme.variant.heading()).color(palette.content_muted),
1385                            );
1386                            open = Some(theme.variant);
1387                        }
1388                        ui.selectable_value(
1389                            value,
1390                            theme.id.to_owned(),
1391                            RichText::new(format!("{}  {}", theme.name, theme.contrast.badge()))
1392                                .color(option_color(value, theme.id, palette)),
1393                        );
1394                    }
1395                })
1396                .response
1397        }
1398    }
1399}
1400
1401/// What a theme picker's closed control reads.
1402///
1403/// [`chosen_text`]'s counterpart, and it is separate for the reason
1404/// [`Control::Themed`] is: the label lives on a [`makeover_layout::ThemeChoice`]
1405/// rather than on a [`Choice`], and the follow row is a third place to look.
1406///
1407/// No placeholder arm. A theme picker is never unanswered in the way a select
1408/// is — an app that resolved a theme to paint this control with has one — and
1409/// falling back to the raw value is the honest report on a stored id whose
1410/// theme has since been deleted.
1411fn themed_text<'a>(field: &'a Field<'a>, value: &'a str) -> &'a str {
1412    if let Some(follow) = field.follows
1413        && follow.value == value
1414    {
1415        return follow.label;
1416    }
1417    field
1418        .themes
1419        .iter()
1420        .find(|theme| theme.id == value)
1421        .map_or(value, |theme| theme.name)
1422}
1423
1424/// One field, as the column the app drops into its form.
1425///
1426/// The anatomy is `makeover-webview`'s, so the two renderers put a form
1427/// together the same way: label, control, hint, error, top to bottom, with a
1428/// checkbox labelling itself instead of taking a label above.
1429///
1430/// Returns [`None`] for a [`FieldKind::Hidden`] field, which is what
1431/// [`FieldKind::visible`] means and is the honest answer here: a webview still
1432/// emits an input for it because the form submits, and an immediate-mode
1433/// renderer has no form and no submission, so a hidden field is a value the app
1434/// already holds and there is nothing to draw or to respond to.
1435///
1436/// `state` is the description's interaction axis.
1437/// [`State::Disabled`] greys the field and stops it answering, through
1438/// [`State::suppresses_interaction`] rather than through a second reading of
1439/// what disabled means. Focus is not on that axis and never reaches here: egui
1440/// owns reach, focus and the ring for this renderer, and one ring means not a
1441/// second one per renderer that happens to have opinions.
1442pub fn field(
1443    ui: &mut Ui,
1444    field: &Field<'_>,
1445    filling: Filling<'_>,
1446    state: Option<State>,
1447    palette: &Palette,
1448    style: &FieldStyle,
1449) -> Option<Response> {
1450    if !field.kind.visible() {
1451        return None;
1452    }
1453    let enabled = !state.is_some_and(State::suppresses_interaction);
1454    let text = if enabled {
1455        palette.content
1456    } else {
1457        palette.content_muted
1458    };
1459
1460    let response = ui
1461        .vertical(|ui| {
1462            ui.spacing_mut().item_spacing.y = style.gap;
1463
1464            // A checkbox labels itself, on the right of the box.
1465            // `FieldKind::labels_itself` is the description saying so, and both
1466            // webview apps special-cased it inline before it did.
1467            let named_by = (!field.kind.labels_itself())
1468                .then(|| ui.label(RichText::new(label_text(field, style)).color(text)));
1469
1470            let response = ui
1471                .add_enabled_ui(enabled, |ui| {
1472                    control(
1473                        ui,
1474                        field,
1475                        filling,
1476                        palette,
1477                        style,
1478                        named_by.as_ref().map(|l| l.id),
1479                    )
1480                })
1481                .inner;
1482
1483            // The label, attached rather than merely adjacent.
1484            //
1485            // Drawing it above the control and stopping there is what this did
1486            // until 2026-08-22, and it put an unnamed box in the accessibility
1487            // tree with some text near it: a screen reader announced a text
1488            // field with no question, and a prefilled one announced its own
1489            // contents instead. audiofiles' four name modals were the site that
1490            // measured it, through a harness reading what the panel drew.
1491            //
1492            // Worth stating why it was worth fixing here rather than in each
1493            // app: `Field::label` is a member the description carries so a
1494            // renderer does not have to guess, `makeover-webview` has always
1495            // named it in `aria-describedby`, and the two renderers disagreeing
1496            // about a fact the description states is the one thing this layer
1497            // exists to prevent. A checkbox is unaffected -- egui names one from
1498            // its own text, which is what `labels_itself` already says.
1499            let response = match named_by {
1500                Some(label) => response.labelled_by(label.id),
1501                None => response,
1502            };
1503
1504            // Standing help, then what the answer costs, then what is wrong
1505            // now. All three, in that order, for the reason the webview
1506            // renderer names all three in `aria-describedby`: an error
1507            // appearing must not take the hint away with it. This host has the
1508            // room, so unlike makeover-tui it never has to choose -- the
1509            // precedence rule on `Field::note` is for the renderer that does.
1510            if let Some(hint) = field.hint {
1511                ui.label(RichText::new(hint).color(palette.content_muted));
1512            }
1513            // The note carries its own tone, and `Palette::tone` is what
1514            // resolves it, so a Neutral note is ordinary content rather than
1515            // a colour this renderer picked.
1516            if let Some((tone, note)) = field.note {
1517                ui.label(RichText::new(note).color(palette.tone(tone)));
1518            }
1519            if let Some(error) = field.error {
1520                ui.label(RichText::new(error).color(palette.danger));
1521            }
1522            response
1523        })
1524        .inner;
1525
1526    Some(response)
1527}
1528
1529/// A set of fields, laid down a column.
1530///
1531/// `show_extended` is the disclosure, and it is a parameter rather than state
1532/// held here because the disclosure belongs to the *form* and not to any field:
1533/// [`Field::extended`] marks which fields are behind one, and the app owns
1534/// whether it is open. That is the same division `makeover-webview` draws when
1535/// it marks the group `data-extended` and emits no control to toggle it.
1536///
1537/// `draw` is called once per field that should be visible, in order. Taking a
1538/// callback rather than a slice of [`Filling`]s is what keeps the app's own
1539/// values borrowed one at a time: a form's fields usually live in different
1540/// structs, and a parallel array would have to be built each frame and kept in
1541/// step with the description by hand.
1542pub fn group<'a>(
1543    ui: &mut Ui,
1544    fields: &'a [Field<'a>],
1545    show_extended: bool,
1546    style: &FieldStyle,
1547    mut draw: impl FnMut(&mut Ui, &'a Field<'a>),
1548) {
1549    ui.vertical(|ui| {
1550        ui.spacing_mut().item_spacing.y = style.group_gap;
1551        for f in fields {
1552            if f.extended && !show_extended {
1553                continue;
1554            }
1555            draw(ui, f);
1556        }
1557    });
1558}
1559
1560#[cfg(test)]
1561mod tests;