Skip to main content

teksilo_core/
build_context.rs

1// SPDX-License-Identifier: MPL-2.0
2// SPDX-FileCopyrightText: 2026 FernTech
3
4//! BuildContext — context available during Widget::build().
5//!
6//! Provides Signal-based APIs for creating reactive state, registering
7//! effects, and adding child widgets during the build lifecycle.
8
9use crate::binding::BindingRegistry;
10use crate::event_source::{SubscriptionHandle, SubscriptionId};
11use crate::signal::{ObserverHandle, Signal};
12use crate::widget_id::WidgetId;
13
14/// Context available during Widget::build().
15pub struct BuildContext<'a> {
16    pub(crate) tree: &'a mut crate::widget_tree::WidgetTree,
17    pub(crate) composite_id: Option<WidgetId>,
18    /// RAII handles for effects registered during this build cycle.
19    /// Transferred to the arena node's `effect_handles` after build returns.
20    pub(crate) effect_handles: Vec<ObserverHandle>,
21    /// Backend-event subscription handles registered during this build
22    /// cycle via `subscribe_event`. Transferred to the arena node's
23    /// `subscription_handles` after build returns.
24    pub(crate) subscription_handles: Vec<(SubscriptionId, SubscriptionHandle)>,
25    /// The `SubscriptionId`s the **previous** build of this same widget used, in the
26    /// order it created them. Empty on a first mount.
27    ///
28    /// A subscription's id is what crosses the thread boundary: the publisher-side
29    /// wrapper captures it by value and posts it, and the UI thread looks it up some
30    /// frames later. Minting a fresh id on every rebuild therefore silently destroys
31    /// every event already in flight, because `rebuild_single_widget` removes the
32    /// previous build's callbacks before `build()` runs and the queued event then names
33    /// an id nothing answers to. Re-using the ids here makes a subscription's identity
34    /// span the rebuilds of one widget, so an event posted before a rebuild is delivered
35    /// to the closure the *new* build installed.
36    ///
37    /// Matched **by position**, which is what makes it cheap and predictable: the Nth
38    /// `subscribe_event`/`subscribe_event_with_ctx` call of this build re-uses the id of
39    /// the Nth call of the last one. A build that subscribes fewer times simply leaves
40    /// the surplus ids unclaimed and they stay torn down; one that subscribes more
41    /// allocates fresh ids for the extras.
42    pub(crate) reusable_sub_ids: Vec<SubscriptionId>,
43}
44
45impl<'a> BuildContext<'a> {
46    /// The WidgetId of the widget being built.
47    pub fn self_id(&self) -> WidgetId {
48        self.composite_id
49            .expect("self_id() called outside of build()")
50    }
51
52    /// Add a widget to the tree.
53    pub fn add(&mut self, widget: impl crate::widget::Widget + 'static) -> WidgetId {
54        self.tree.add(widget)
55    }
56
57    /// Add a pre-boxed widget to the tree.
58    pub fn add_boxed(&mut self, widget: Box<dyn crate::widget::Widget>) -> WidgetId {
59        self.tree.add_boxed(widget)
60    }
61
62    /// Add a **parentless** widget this one owns: pre-built overlay content
63    /// (a dropdown menu, a date picker's calendar, a tooltip's nested cascade
64    /// children) that must not be reached by the child walk.
65    ///
66    /// Use this — never a bare [`add`](Self::add) — for anything built ahead of
67    /// time and parked with [`set_dormant`](Self::set_dormant) to be shown later
68    /// through an overlay. The two differ only in bookkeeping: `add` hands back
69    /// a node nothing owns, so the builder's own teardown cannot reach it and
70    /// every rebuild strands another copy in the arena; this records the
71    /// ownership edge, so the node dies with its owner and the previous
72    /// generation dies with each rebuild.
73    ///
74    /// Content that *can* be a child should be returned from `build()` as one
75    /// instead. This exists for content that cannot: activation and the paint
76    /// walk both descend through `children`, so a dormant popup parked there
77    /// wakes with its host and paints inline at zero size.
78    pub fn add_detached(&mut self, widget: impl crate::widget::Widget + 'static) -> WidgetId {
79        self.add_detached_boxed(Box::new(widget))
80    }
81
82    /// Insert a child whose subtree is **not built until `reveal` first turns
83    /// true**, and is retained from then on. Returns the host's id immediately.
84    ///
85    /// The shape this replaces is `ctx.add(panel)` followed by
86    /// `ctx.set_dormant(id)` — correct, but it builds content the user may never
87    /// open, on every rebuild of the owner. In a virtualized collection the
88    /// owner is a per-row delegate, so that cost is multiplied by the row count:
89    /// on a 40-row table whose cells each carried a four-item menu, the eager
90    /// form cost 325–552 ms per rebuild against 42–46 ms without the column at
91    /// all, and ~85% of it was the `add` rather than constructing the widget
92    /// value. See [`DeferredSubtree`](crate::deferred_subtree::DeferredSubtree)
93    /// for the full contract.
94    ///
95    /// Pass the same signal the content's `visible_when` gate uses. Everything
96    /// downstream of the returned id — `set_dormant` / `activate`,
97    /// `visible_when`, `OverlayRequest::content_id`, descendant checks,
98    /// dismissal — is unchanged; only when the subtree below it exists moves.
99    pub fn add_deferred(
100        &mut self,
101        reveal: crate::signal::Signal<bool>,
102        widget: impl crate::widget::Widget + 'static,
103    ) -> WidgetId {
104        self.add_deferred_boxed(reveal, Box::new(widget))
105    }
106
107    /// [`add_deferred`](Self::add_deferred) for an already-boxed widget.
108    pub fn add_deferred_boxed(
109        &mut self,
110        reveal: crate::signal::Signal<bool>,
111        widget: Box<dyn crate::widget::Widget>,
112    ) -> WidgetId {
113        self.add(crate::deferred_subtree::DeferredSubtree::new(
114            Some(reveal),
115            widget,
116        ))
117    }
118
119    /// [`add_deferred`](Self::add_deferred) for content the **framework**
120    /// materializes, kept as a child of the builder.
121    ///
122    /// The parented twin of
123    /// [`add_detached_deferred_on_demand`](Self::add_detached_deferred_on_demand),
124    /// for the two rich-tooltip attach paths: they have always parented their
125    /// body on the anchor's owner, and reparenting them to `detached` would move
126    /// which teardown reaps them. Only *when* the body is built changes.
127    ///
128    /// Worth the separate entry point because a rich tooltip is not one widget:
129    /// `RichTooltipWidget::build` eagerly pre-creates a nested tooltip for every
130    /// `:key` link in its body, recursively, so one attached tip expands into a
131    /// cascade. Built eagerly on a data view's row delegate, 29 rows of
132    /// Skribisto's Overview carried 1,305 tooltip widgets inside a 22,737-node
133    /// subtree, and tearing that down cost 5.3 s per arrow-key press — the
134    /// destroy, not the build.
135    pub fn add_deferred_on_demand(
136        &mut self,
137        widget: impl crate::widget::Widget + 'static,
138    ) -> WidgetId {
139        self.add(crate::deferred_subtree::DeferredSubtree::new(
140            None,
141            Box::new(widget),
142        ))
143    }
144
145    /// [`add_deferred`](Self::add_deferred) for content the **framework**
146    /// materializes rather than a widget's own open signal.
147    ///
148    /// The tooltip case: a tooltip body has no open signal a widget could hand
149    /// over — the tree decides, when a dwell matures. `WidgetTree` forces such
150    /// a host just before it consults `Widget::tooltip_has_content`, so the
151    /// body exists by the time anything asks it a question.
152    pub fn add_detached_deferred_on_demand(
153        &mut self,
154        widget: impl crate::widget::Widget + 'static,
155    ) -> WidgetId {
156        self.add_detached(crate::deferred_subtree::DeferredSubtree::new(
157            None,
158            Box::new(widget),
159        ))
160    }
161
162    /// [`add_deferred`](Self::add_deferred), inserted detached — the shape
163    /// overlay content wants, so it is owned by the builder and dies with it
164    /// rather than outliving every menu the user ever opened.
165    pub fn add_detached_deferred_boxed(
166        &mut self,
167        reveal: crate::signal::Signal<bool>,
168        widget: Box<dyn crate::widget::Widget>,
169    ) -> WidgetId {
170        self.add_detached(crate::deferred_subtree::DeferredSubtree::new(
171            Some(reveal),
172            widget,
173        ))
174    }
175
176    /// [`add_detached_deferred_boxed`](Self::add_detached_deferred_boxed) for an
177    /// unboxed widget.
178    pub fn add_detached_deferred(
179        &mut self,
180        reveal: crate::signal::Signal<bool>,
181        widget: impl crate::widget::Widget + 'static,
182    ) -> WidgetId {
183        self.add_detached_deferred_boxed(reveal, Box::new(widget))
184    }
185
186    /// [`add_detached`](Self::add_detached) for an already-boxed widget.
187    pub fn add_detached_boxed(&mut self, widget: Box<dyn crate::widget::Widget>) -> WidgetId {
188        let id = self.tree.add_boxed(widget);
189        let owner = self.self_id();
190        self.tree.record_detached(owner, id);
191        id
192    }
193
194    /// Add a Level 2 widget as a child of another widget.
195    pub fn add_child(
196        &mut self,
197        parent: WidgetId,
198        widget: impl crate::widget::Widget + 'static,
199    ) -> WidgetId {
200        self.tree.add_child(parent, widget)
201    }
202
203    // --- Signal APIs ---
204
205    /// Create a new mutable signal.
206    pub fn signal<T: 'static>(&mut self, value: T) -> Signal<T> {
207        Signal::new(value)
208    }
209
210    /// Create a new `Signal<f32>` that supports `animate_to()`.
211    /// Registered with the animation scheduler automatically. The owning
212    /// widget (`self_id()`) is recorded so that the scheduler can pause
213    /// the animation when the widget is offscreen, dormant, or rebuilt.
214    pub fn animated_signal(&mut self, value: f32) -> Signal<f32> {
215        let signal = Signal::new_animated(value);
216        let owner = self.self_id();
217        self.tree.register_animated_signal(&signal, owner);
218        signal
219    }
220
221    /// Register a pre-existing `Signal<f32>` for animation support.
222    /// Use this when the signal was created outside of `build()` (e.g. in the
223    /// widget constructor) and needs to be registered with the animation scheduler.
224    pub fn register_animated_signal(&mut self, signal: &Signal<f32>) {
225        let owner = self.self_id();
226        self.tree.register_animated_signal(signal, owner);
227    }
228
229    /// Read the OS-level `prefers-reduced-motion` preference. Widgets
230    /// that use looping or decorative animations (spinners, sprite
231    /// icons, marquee text, etc.) should skip starting them when this
232    /// returns `true` so the UI respects accessibility settings and —
233    /// as a bonus — draws no CPU/GPU.
234    pub fn prefers_reduced_motion(&self) -> bool {
235        self.tree.prefers_reduced_motion()
236    }
237
238    /// Build an [`AnimationSpec`](crate::animation_builder::AnimationSpec)
239    /// — the fluent ergonomic façade over `Signal<f32>::animate_to`.
240    /// Captures the theme's `MotionTokens` and the platform
241    /// reduced-motion preference at build time, returns a clonable
242    /// spec that event-handler closures can drive without
243    /// re-threading durations and easing.
244    ///
245    /// ```ignore
246    /// let knob_anim = ctx.animate().fast().standard();
247    /// handlers = handlers.on_tap(move |_, _| {
248    ///     knob_anim.to_or_snap(&knob_position, target);
249    /// });
250    /// ```
251    pub fn animate(&self) -> crate::animation_builder::AnimationSpec {
252        crate::animation_builder::AnimationSpec::from_motion(
253            self.theme().motion.clone(),
254            self.prefers_reduced_motion(),
255        )
256    }
257
258    /// Opt into the shader-driven animated-quad pipeline. The widget
259    /// paint() emits ONE `canvas.draw_animated_quad(bounds, handle.slot(),
260    /// class)` call; the renderer samples per-slot state from its
261    /// uniform buffer each frame and the widget's paint() does not
262    /// re-run for animation ticks — only on layout changes. The
263    /// returned handle is stable for the widget-mount lifetime and
264    /// should be stashed on `self` to thread to `paint()`.
265    ///
266    /// For decorative motion that isn't a quad (scroll-offset tweens,
267    /// sidebar slide, toggle knob), keep using `ctx.animated_signal` +
268    /// `signal.animate_looping` — both paths coexist.
269    pub fn animated_quad(
270        &mut self,
271        kind: crate::animated_quad::AnimatedQuadKind,
272    ) -> crate::animated_quad::AnimatedQuadHandle {
273        let owner = self.self_id();
274        self.tree.register_animated_quad(owner, kind)
275    }
276
277    /// The per-frame delta-seconds signal. Observe it via
278    /// `ctx.effect(&ctx.frame_tick(), |delta| ...)` to run code once per
279    /// frame **the tree was explicitly asked to pump**. Merely observing
280    /// this signal does not keep the event loop awake — widgets must
281    /// call [`request_frame`](Self::request_frame) (typically from an
282    /// event handler or from inside the tick closure itself) to schedule
283    /// the next wake-up. This preserves Teksilo's draw-when-needed model.
284    pub fn frame_tick(&self) -> Signal<f32> {
285        self.tree.frame_tick()
286    }
287
288    /// Ask the tree to pump exactly one more frame. See
289    /// [`frame_tick`](Self::frame_tick) for the observer side.
290    pub fn request_frame(&self) {
291        self.tree.request_frame();
292    }
293
294    /// Request that the AccessKit tree be re-walked after this build pass.
295    /// Use when `build()` restructured its subtree in a way that changes the
296    /// accessibility tree (relayout alone no longer re-walks AT). `SceneView`
297    /// calls this each build, since it may have materialised or destroyed
298    /// scene widgets or applied a11y-only scene mutations.
299    pub fn request_accessibility_update(&self) {
300        self.tree.request_accessibility_update();
301    }
302
303    /// Speak `message` to the screen reader, politely.
304    ///
305    /// The build-time companion to
306    /// [`EventContext::announce`](crate::widget::EventContext::announce), for a
307    /// widget that discovers during `build()` that something needs saying — an
308    /// error surface appearing, a result count changing. Announcing from
309    /// `build()` announces once per *rebuild*, so guard it on a real change
310    /// rather than on the build itself.
311    pub fn announce(&mut self, message: impl Into<String>) {
312        self.tree.announce(message);
313    }
314
315    /// Speak `message` to the screen reader at the given urgency. See
316    /// [`EventContext::announce_with`](crate::widget::EventContext::announce_with).
317    pub fn announce_with(
318        &mut self,
319        message: impl Into<String>,
320        politeness: crate::announcer::Politeness,
321    ) {
322        self.tree.announce_with(message, politeness);
323    }
324
325    /// Clone the shared "frame requested" flag. Stash it on widget
326    /// state and call `.set(true)` from inside a frame-tick effect
327    /// closure to chain-request another frame without needing
328    /// mutable access to the tree. Used by widgets with continuous
329    /// frame needs (caret blink, drag auto-scroll, smooth
330    /// animations driven from a tick closure).
331    ///
332    /// **Prefer [`subscribe_frame_tick`](Self::subscribe_frame_tick)**
333    /// for visual-only continuous animations (Pulse, Cycle, …): the
334    /// scheduler-backed path automatically pauses the chain when the
335    /// owner widget is hidden, while this raw handle keeps the event
336    /// loop pumping at full frame rate regardless of visibility.
337    pub fn frame_request_handle(&self) -> std::rc::Rc<std::cell::Cell<bool>> {
338        self.tree.frame_request_handle()
339    }
340
341    /// Subscribe the widget being built to the per-frame-effect
342    /// scheduler. The returned RAII guard removes the subscription on
343    /// drop — store it on `self` so its lifetime tracks the widget's.
344    ///
345    /// While at least one subscriber's owner is visible, the framework
346    /// auto-arms `frame_tick_requested` after every render. When all
347    /// subscribers are hidden (e.g. parked inside a non-selected
348    /// `Switcher` branch), no re-arm happens and the chain dies, so
349    /// the event loop sleeps. On a hidden→visible transition the
350    /// `visible_when` binding's relayout dirty triggers a repaint that
351    /// paints the subscriber, which the post-render arm then detects
352    /// and resumes the chain.
353    ///
354    /// Replaces the widget-managed `frame_request.set(true)` re-arm
355    /// pattern for visual-only continuous animations. The widget's
356    /// `frame_tick` effect closure no longer needs to call
357    /// `frame_request.set(true)` itself — the scheduler handles it.
358    pub fn subscribe_frame_tick(&self) -> crate::frame_tick_scheduler::FrameTickSubscription {
359        let sub = self.tree.subscribe_frame_tick(self.self_id());
360        // Bootstrap: ensure at least one frame runs after registration
361        // so the first paint happens. The post-render re-arm takes over
362        // from there. This is also the resume nudge for the case where
363        // a widget rebuilds (e.g. due to a state change) while still
364        // hidden — the parent's relayout dirty will trigger paint, and
365        // post-render arm will pick up the chain.
366        self.tree.request_frame();
367        sub
368    }
369
370    /// Like [`subscribe_frame_tick`](Self::subscribe_frame_tick), but the
371    /// widget only needs to wake **at most once per `interval`** while
372    /// visible. Same visibility gate and RAII guard; between wakes the
373    /// event loop sleeps to the interval deadline rather than rendering
374    /// identical 60 fps frames. Use when the widget's visible output
375    /// changes far less often than 60 Hz — e.g. `Cycle`'s once-per-period
376    /// index advance, or a seconds-granular clock.
377    pub fn subscribe_frame_tick_throttled(
378        &self,
379        interval: std::time::Duration,
380    ) -> crate::frame_tick_scheduler::FrameTickSubscription {
381        let sub = self
382            .tree
383            .subscribe_frame_tick_throttled(self.self_id(), interval);
384        // Bootstrap the first frame after registration (see
385        // `subscribe_frame_tick`).
386        self.tree.request_frame();
387        sub
388    }
389
390    /// Clone the shared wake-at deadline cell. Stash it on widget
391    /// state and set `Some(instant)` from a frame-tick effect to
392    /// schedule a one-shot deadline wake-up without keeping the event
393    /// loop in `Poll` mode. See `WidgetTree::wake_at_handle` for
394    /// the underlying mechanism.
395    pub fn wake_at_handle(&self) -> std::rc::Rc<std::cell::Cell<Option<std::time::Instant>>> {
396        self.tree.wake_at_handle()
397    }
398
399    /// Register a scoped effect tied to this build cycle.
400    /// The effect fires whenever the signal changes. It is automatically
401    /// cleaned up on rebuild or widget destruction.
402    pub fn effect<T: Clone + 'static>(&mut self, signal: &Signal<T>, f: impl Fn(&T) + 'static) {
403        let handle = signal.observe(f);
404        self.effect_handles.push(handle);
405    }
406
407    /// Register a pre-existing observer handle for lifecycle management.
408    /// The handle will be dropped (and the observer removed) on rebuild
409    /// or widget destruction.
410    pub fn own_handle(&mut self, handle: ObserverHandle) {
411        self.effect_handles.push(handle);
412    }
413
414    /// Get the binding registry.
415    pub fn binding_registry(&self) -> &BindingRegistry {
416        self.tree.binding_registry()
417    }
418
419    /// Get the current theme.
420    pub fn theme(&self) -> &crate::styles::Theme {
421        self.tree.theme()
422    }
423
424    /// Reactive handle on the current theme. Fires observers when
425    /// `tree.set_theme(...)` is called. Build implementations that want
426    /// theme-driven values to update without a rebuild should use this
427    /// instead of cloning tokens from `self.theme()` — for example,
428    /// `ctx.theme_signal().map(|t| t.colors.primary)` or combining with
429    /// interaction state via `zip(...)`.
430    pub fn theme_signal(&self) -> crate::signal::Signal<crate::styles::Theme> {
431        self.tree.theme_signal().clone()
432    }
433
434    /// Current combined text-scale factor (`user × OS`, `1.0` = 100 %). One-shot
435    /// read for build-time sizing; for a value that updates without a rebuild,
436    /// bind [`text_scale_signal`](Self::text_scale_signal) instead.
437    pub fn text_scale(&self) -> f32 {
438        self.tree.effective_text_scale()
439    }
440
441    /// Reactive handle on the combined text-scale factor. Fires when the user
442    /// scale, theme, or OS text-scale preference changes. Build implementations
443    /// that derive a build-time dimension from the scale (e.g. `Calendar`'s
444    /// fixed cell sizes) bind this — typically at `Rebuild` level so the change
445    /// recomputes the constants — since a scale change relayouts but does not
446    /// rebuild on its own.
447    pub fn text_scale_signal(&self) -> crate::signal::Signal<f32> {
448        self.tree.text_scale_signal()
449    }
450
451    /// Whether the host window is currently active (`focused AND not
452    /// occluded`). One-shot read for build-time use; for a value that reacts
453    /// to focus changes, bind [`window_active_signal`](Self::window_active_signal).
454    pub fn window_active(&self) -> bool {
455        self.tree.is_window_active()
456    }
457
458    /// Reactive handle on window-active state. Fires when the host window gains
459    /// or loses active status (`focused AND not occluded`). Build
460    /// implementations that show/hide appearance with window focus — caret
461    /// effects, the selection-colour swap in text fields, `DimWhenInactive` —
462    /// bind this, typically at `RepaintOnly` level (an active-state flip never
463    /// affects geometry). Starts `true`.
464    pub fn window_active_signal(&self) -> crate::signal::Signal<bool> {
465        self.tree.window_active_signal()
466    }
467
468    /// Reactive handle on the current locale. Fires observers when
469    /// `tree.set_locale(...)` is called.
470    pub fn locale_signal(&self) -> crate::signal::Signal<Option<String>> {
471        self.tree.locale_signal().clone()
472    }
473
474    /// The [`WindowState`](crate::window::WindowState) for the window
475    /// hosting this tree. `None` only for trees built outside of an
476    /// app (tests, headless scenarios). Use this to bind widgets to
477    /// window-level signals like `placement`, `size`, `focused`.
478    pub fn window(&self) -> Option<&crate::window::WindowState> {
479        self.tree.window_state()
480    }
481
482    /// Retrieve an application-scoped value of type `T` registered via
483    /// `TeksiloAppBuilder::app_state`. Returns `None` if no value of
484    /// that type was registered. The returned reference borrows from
485    /// the framework for the duration of the build pass.
486    pub fn app_state<T: 'static>(&self) -> Option<&T> {
487        self.tree.app_context().app_state::<T>()
488    }
489
490    /// Borrow the [`AppEventPoster`](crate::AppEventPoster) installed by the
491    /// framework, if any. Mirrors [`EventContext::poster`](crate::widget::EventContext::poster).
492    /// Used by integrations that wire a platform callback (e.g. a native menu
493    /// item) to post a typed payload back to the UI loop. Returns `None` for
494    /// trees built outside an app (tests / headless).
495    pub fn poster(&self) -> Option<&std::sync::Arc<dyn crate::AppEventPoster>> {
496        self.tree.app_context().poster()
497    }
498
499    /// Bind a widget's visibility to a boolean prop or compatibility state binding.
500    pub fn visible_when(&mut self, id: WidgetId, state: impl Into<crate::signal::Prop<bool>>) {
501        self.tree.visible_when(id, state);
502    }
503
504    /// Enqueue a one-shot action to run shortly after this build, with a real
505    /// [`EventContext`](crate::widget::EventContext) — the only place a widget
506    /// can read the OS parent window handle (`ctx.parent_window_handle()`),
507    /// `app_state`, and `poster` *together*, after it is mounted under its
508    /// window. The action runs at most once per enqueue (the app loop drains
509    /// the queue each iteration); a widget that rebuilds must guard against
510    /// enqueuing twice. Built for widgets owning a native OS resource that
511    /// needs a window handle to initialise (a `WebView`'s engine subview);
512    /// ordinary widgets never need it.
513    pub fn run_after_mount(&mut self, f: impl FnOnce(&mut crate::widget::EventContext) + 'static) {
514        self.tree.queue_mount_action(Box::new(f));
515    }
516
517    /// Observe a node's framework activation as a `Signal<bool>` — `true`
518    /// while active, `false` while parked dormant by a `Switcher` /
519    /// `visible_when` gate. Initialised to the node's current state and
520    /// updated only on an actual Active↔Dormant transition.
521    ///
522    /// Ordinary widgets never need this: dormant subtrees are simply not
523    /// painted, so they vanish for free. It exists for the one case where
524    /// "not painted" ≠ "hidden" — a widget owning a native OS resource
525    /// that renders *outside* the wgpu pass (a `WebView`'s engine subview).
526    /// Such a widget does `ctx.effect(&ctx.activation_signal(id), move |a|
527    /// handle.set_visible(*a))` to hide/show the native surface in lockstep.
528    pub fn activation_signal(&mut self, id: WidgetId) -> Signal<bool> {
529        self.tree.activation_signal(id)
530    }
531
532    /// Reactive `Signal<bool>` that is `true` while the *focus scope* containing
533    /// the widget being built — its nearest focusable ancestor, e.g. the
534    /// enclosing `ListView` / `TreeView` — holds keyboard focus. Items outside
535    /// any focusable scope read a constant `true`.
536    ///
537    /// Drives **focus-aware selection**: a selected row renders with the active
538    /// `Selected` chrome while its view has focus and the muted
539    /// `SelectedInactive` chrome when focus moves elsewhere — the standard
540    /// desktop affordance (Qt `SH_ItemView_...`, macOS inactive selection) that
541    /// shows where the keyboard is. The scope is resolved at build time but the
542    /// signal stays live across focus changes.
543    pub fn view_focus_active(&mut self) -> Signal<bool> {
544        // Prefer the scope a containing data view explicitly established for its
545        // rows (deterministic, parenting-independent); else resolve by walking
546        // to the nearest focusable ancestor.
547        if let Some(scope) = self.tree.current_view_focus() {
548            return scope;
549        }
550        let id = self.self_id();
551        self.tree.view_focus_active_for(id)
552    }
553
554    /// Mark the widget being built as a **focus scope** for the rows/items it
555    /// builds next: any descendant's [`view_focus_active`](Self::view_focus_active)
556    /// (and `StandardItem`'s focus-aware selection / focus ring) reads *this*
557    /// widget's keyboard focus. A data view calls this around its row loop, then
558    /// [`end_view_focus`](Self::end_view_focus). Deterministic — unaffected by
559    /// arena parenting, which may not be wired while docked/virtualized rows build.
560    pub fn begin_view_focus(&mut self) -> Signal<bool> {
561        let id = self.self_id();
562        self.tree.begin_view_focus(id)
563    }
564
565    /// Like [`begin_view_focus`](Self::begin_view_focus) but keys the scope on
566    /// an explicit `node_id` rather than the widget being built. A view whose
567    /// rows are built by a **separate body-pane widget** (TableView /
568    /// TreeTableView / GridView) passes its own focusable root id so descendant
569    /// items resolve the *root's* keyboard focus — not the pane's, which is a
570    /// child of the root and so never holds focus itself.
571    pub fn begin_view_focus_for(&mut self, node_id: WidgetId) -> Signal<bool> {
572        self.tree.begin_view_focus(node_id)
573    }
574
575    /// End the focus scope opened by [`begin_view_focus`](Self::begin_view_focus).
576    pub fn end_view_focus(&mut self) {
577        self.tree.end_view_focus();
578    }
579
580    /// Input-modality "focus-visible" signal — `true` after keyboard input,
581    /// `false` after pointer input (the standard `:focus-visible` rule). Pair
582    /// with [`view_focus_active`](Self::view_focus_active) to draw a focus
583    /// ring only during keyboard navigation, not on mouse clicks.
584    pub fn focus_visible(&self) -> Signal<bool> {
585        self.tree.focus_visible_signal()
586    }
587
588    /// Bind an opacity multiplier (0..1) to a widget. The render walker
589    /// emits `SetOpacity(value)` before painting the widget's subtree
590    /// and `RestoreOpacity` afterwards, so the multiplier composes
591    /// correctly with ancestor opacity scopes. Bound at `RepaintOnly`:
592    /// opacity changes never trigger relayout. Used by the `Fade`
593    /// wrapper to animate a child between hidden and fully visible.
594    pub fn set_opacity(&mut self, id: WidgetId, opacity: impl Into<crate::signal::Prop<f32>>) {
595        self.tree.set_opacity(id, opacity);
596    }
597
598    /// Bind a 2D affine transform to a widget. The render walker emits
599    /// `PushTransform(value)` before painting the widget's subtree and
600    /// `PopTransform` afterwards, so the transform composes onto the
601    /// renderer's stack with any ancestor transform scopes and with
602    /// the widget's own canvas-level transforms. Bound at `RepaintOnly`:
603    /// visual-only transforms never trigger relayout. Used by `Scale`
604    /// and `Rotate`; reflow-driving wrappers (e.g. `Scale::reflow(true)`)
605    /// must additionally bind their driver signal to themselves at
606    /// `Relayout` to make layout track the value.
607    pub fn set_transform(
608        &mut self,
609        id: WidgetId,
610        transform: impl Into<crate::signal::Prop<teksilo_canvas::Transform2D>>,
611    ) {
612        self.tree.set_transform(id, transform);
613    }
614
615    /// Bind a 2D affine **content** transform to a widget — the transform
616    /// positions the widget's content within its fixed parent-space viewport
617    /// (its bounds) rather than transforming the widget itself. Renders the
618    /// same `PushTransform` / `PopTransform` scope as
619    /// [`set_transform`](Self::set_transform), but hit-testing treats the
620    /// bounds as a fixed viewport so the whole visible area stays interactive
621    /// at any pan / zoom. Used by `SceneView` for its pan/zoom view transform.
622    pub fn set_content_transform(
623        &mut self,
624        id: WidgetId,
625        transform: impl Into<crate::signal::Prop<teksilo_canvas::Transform2D>>,
626    ) {
627        self.tree.set_content_transform(id, transform);
628    }
629
630    /// Bind a Gaussian-equivalent blur radius to a widget. The render
631    /// walker emits `BeginBlurredSubtree { bounds, radius }` before
632    /// painting the widget's subtree and `EndBlurredSubtree` afterwards;
633    /// the renderer redirects drawing into an intermediate texture, runs
634    /// a dual-Kawase blur chain at the requested radius, and composites
635    /// the blurred result back into the parent pass at the widget's
636    /// bounds. Bound at `RepaintOnly`: blur radius changes never trigger
637    /// relayout. Sub-perceptual radii (< 0.5) skip the Begin/End pair
638    /// entirely so animated enable/disable patterns have zero per-frame
639    /// cost when fully off. Used by the `Blur` wrapper.
640    pub fn set_blur(&mut self, id: WidgetId, radius: impl Into<crate::signal::Prop<f32>>) {
641        self.tree.set_blur(id, radius);
642    }
643
644    /// Bind a widget's enabled state to a boolean prop or compatibility state binding.
645    pub fn enabled_when(&mut self, id: WidgetId, state: impl Into<crate::signal::Prop<bool>>) {
646        self.tree.enabled_when(id, state);
647    }
648
649    /// Reactive view of "is this widget effectively enabled?" — the AND
650    /// of the widget's own `enabled_state` and every ancestor's. The
651    /// arena's [`crate::arena::WidgetArena::is_enabled`] is the
652    /// non-reactive equivalent; this method gives composite widgets a
653    /// `Signal<bool>` they can `.map(...)` / `.zip(...)` against to
654    /// derive other reactive UI state (cursor, custom paint, helper
655    /// signals).
656    ///
657    /// Leaves like `IconWidget` / `TextWidget` / `RectWidget` do NOT
658    /// need this — they get the bool directly via
659    /// [`crate::widget::PaintContext::effective_enabled`] at paint time.
660    /// This method is for composites that need the value at build time
661    /// or want to chain signals.
662    ///
663    /// The signal is node-resident and framework-refreshed (install-or-reuse,
664    /// like [`Self::activation_signal`]), so it tracks ancestors correctly even
665    /// though a widget's parent is not yet wired while its own `build()` runs.
666    /// It is a *mutable* signal, so — unlike the old derived implementation —
667    /// it can be passed to [`Self::effect`].
668    ///
669    /// Returns a signal reading `true` for any node whose entire ancestor
670    /// chain (including itself) has no `enabled_state` bound.
671    pub fn effective_enabled_signal(&mut self, id: WidgetId) -> Signal<bool> {
672        self.tree.effective_enabled_signal(id)
673    }
674
675    /// Bind a widget's Tab-key participation to a boolean prop or
676    /// compatibility state binding. When false, the widget is removed
677    /// from Tab / Shift+Tab traversal but remains reachable via
678    /// `request_focus` and arrow-key navigation. Implements the ARIA
679    /// roving-tabindex pattern (HTML `tabindex="-1"` semantics).
680    pub fn set_tab_stop(&mut self, id: WidgetId, state: impl Into<crate::signal::Prop<bool>>) {
681        self.tree.set_tab_stop(id, state);
682    }
683
684    /// Publish what a data view's `Space` should do when the row containing
685    /// `id` holds the keyboard cursor.
686    ///
687    /// A `ListView` / `TreeView` row is not itself focusable and the view keeps
688    /// the row subtree out of the Tab order — a listbox is one Tab stop — so a
689    /// checkbox inside a row has no keyboard route of its own.
690    /// `StandardListItem` / `StandardTreeItem` publish one for the checkbox
691    /// they embed; a hand-written row delegate calls this to get the same
692    /// behaviour. Without it `Space` keeps meaning "toggle the selection".
693    pub fn set_keyboard_toggle(&mut self, id: WidgetId, f: std::rc::Rc<dyn Fn()>) {
694        self.tree.set_keyboard_toggle(id, f);
695    }
696
697    /// Declare the widget being built as a **traversal-scope boundary** for
698    /// Tab / Shift+Tab navigation. Descendants' `tab_index` values become
699    /// scoped to this node — they never collide with sibling scopes — and the
700    /// `policy` controls what happens at the scope's ends:
701    ///
702    /// - [`TraversalScopePolicy::Continue`](crate::focus::TraversalScopePolicy::Continue)
703    ///   — Tab flows out into the enclosing scope's next member (groups
704    ///   numbering only).
705    /// - [`TraversalScopePolicy::Cycle`](crate::focus::TraversalScopePolicy::Cycle)
706    ///   — Tab wraps within the scope, never exits. For **modal dialogs only**:
707    ///   a popover or menu is non-modal, and the framework closes one the
708    ///   keyboard walks out of rather than containing focus in it. Trapping such
709    ///   an overlay stops that dismissal from ever firing.
710    ///
711    /// This node is automatically excluded from being a Tab stop itself.
712    /// Prefer the `FocusScope` wrapper widget in `teksilo-widgets` over
713    /// calling this directly.
714    pub fn set_traversal_scope(&mut self, policy: crate::focus::TraversalScopePolicy) {
715        let id = self.self_id();
716        self.tree.set_traversal_scope(id, policy);
717    }
718
719    /// Attach a tooltip to a widget.
720    pub fn attach_tooltip(
721        &mut self,
722        anchor_id: WidgetId,
723        content_id: WidgetId,
724        delay: std::time::Duration,
725    ) {
726        self.tree.attach_tooltip(anchor_id, content_id, delay);
727        self.claim_tooltip_description(anchor_id);
728    }
729
730    /// Attach a tooltip with an explicit
731    /// [`TooltipPlacement`](crate::overlay::TooltipPlacement) — use `Side`
732    /// for anchors stacked vertically (menu items, a vertical tab strip,
733    /// list/tree rows) so the tooltip opens beside the anchor instead of
734    /// covering the next sibling.
735    pub fn attach_tooltip_with_placement(
736        &mut self,
737        anchor_id: WidgetId,
738        content_id: WidgetId,
739        delay: std::time::Duration,
740        placement: crate::overlay::TooltipPlacement,
741    ) {
742        self.tree
743            .attach_tooltip_with_placement(anchor_id, content_id, delay, placement);
744        self.claim_tooltip_description(anchor_id);
745    }
746
747    /// Attach a tooltip that auto-promotes to sticky after a dwell
748    /// timer. Non-None `sticky_after` enables the sticky-on-dwell UX:
749    /// once the tooltip has been shown for `sticky_after`, the tree
750    /// flags the entry sticky and swaps the overlay's dismiss
751    /// behavior to `EscapeOrClickOutside`.
752    pub fn attach_tooltip_with_sticky(
753        &mut self,
754        anchor_id: WidgetId,
755        content_id: WidgetId,
756        delay: std::time::Duration,
757        sticky_after: Option<std::time::Duration>,
758    ) {
759        self.tree
760            .attach_tooltip_with_sticky(anchor_id, content_id, delay, sticky_after);
761        self.claim_tooltip_description(anchor_id);
762    }
763
764    /// Variant of [`attach_tooltip_with_sticky`](Self::attach_tooltip_with_sticky)
765    /// that takes a shared `Rc<Cell<Option<Instant>>>` "sink" the
766    /// tree updates whenever the tooltip is shown / dismissed. The
767    /// tooltip widget reads from this sink to compute its own dwell
768    /// progress reliably, without needing a paint-gap heuristic.
769    pub fn attach_tooltip_with_sticky_sink(
770        &mut self,
771        anchor_id: WidgetId,
772        content_id: WidgetId,
773        delay: std::time::Duration,
774        sticky_after: Option<std::time::Duration>,
775        shown_at_sink: std::rc::Rc<std::cell::Cell<Option<std::time::Instant>>>,
776    ) {
777        self.tree.attach_tooltip_with_sticky_sink(
778            anchor_id,
779            content_id,
780            delay,
781            sticky_after,
782            shown_at_sink,
783        );
784        self.claim_tooltip_description(anchor_id);
785    }
786
787    /// Variant of [`attach_tooltip_with_sticky_sink`](Self::attach_tooltip_with_sticky_sink)
788    /// that also carries a [`TooltipPlacement`](crate::overlay::TooltipPlacement).
789    /// The full-featured path used by rich + composite tooltips that want
790    /// `Side` placement in a vertical context (menu items, list/tree rows).
791    pub fn attach_tooltip_with_sticky_sink_placement(
792        &mut self,
793        anchor_id: WidgetId,
794        content_id: WidgetId,
795        delay: std::time::Duration,
796        sticky_after: Option<std::time::Duration>,
797        shown_at_sink: std::rc::Rc<std::cell::Cell<Option<std::time::Instant>>>,
798        placement: crate::overlay::TooltipPlacement,
799    ) {
800        self.tree.attach_tooltip_with_sticky_sink_placement(
801            anchor_id,
802            content_id,
803            delay,
804            sticky_after,
805            shown_at_sink,
806            placement,
807        );
808        self.claim_tooltip_description(anchor_id);
809    }
810
811    /// Name this widget as the one the tooltip just attached describes.
812    ///
813    /// Every `attach_tooltip*` wrapper ends with this, so a composing control
814    /// gets it for free: `Button`, `Toggle` and the two dozen widgets shaped
815    /// like them hang the overlay off an inner chrome node -- the thing with
816    /// the right bounds to open against -- while their role, their name and
817    /// their focusability sit on their own outer node, which is the node an
818    /// assistive technology lands on and therefore the node a description has
819    /// to be on.
820    ///
821    /// A widget anchoring its tooltip on itself claims itself, which is what
822    /// it already had. A widget attaching *many* tooltips in one build -- a
823    /// list body pane, one per visible row -- claims itself for every one of
824    /// them, which is a claim that cannot be granted; the accessibility walk
825    /// is where that is noticed, because it is the only place the whole set
826    /// is visible at once.
827    fn claim_tooltip_description(&mut self, anchor_id: WidgetId) {
828        let owner = self.self_id();
829        self.tree.set_tooltip_description_owner(anchor_id, owner);
830    }
831
832    /// Promote a shown tooltip to "sticky": removes its auto-dismiss
833    /// on pointer-leave and swaps the overlay's dismiss behavior to
834    /// `EscapeOrClickOutside`. Used by rich tooltips that implement a
835    /// dwell timer.
836    pub fn promote_tooltip_to_sticky(&mut self, content_id: WidgetId) {
837        self.tree.promote_tooltip_to_sticky(content_id);
838    }
839
840    /// Set a widget as dormant (inactive). Used to pre-create overlay content
841    /// that will be activated later via `EventContext::activate()`.
842    pub fn set_dormant(&mut self, id: WidgetId) {
843        self.tree.set_dormant(id);
844    }
845
846    /// Destroy a widget and its entire subtree, removing them from the
847    /// arena and dropping any per-widget subscription / effect handles.
848    ///
849    /// Use this to clean up dormant subtrees that the current widget
850    /// created during a prior build and that live outside its regular
851    /// arena children — e.g., a pre-built popup panel inserted via
852    /// `ctx.add(..)` + `ctx.set_dormant(..)` that becomes stale after a
853    /// rebuild. Regular arena children of the composite (i.e. widgets
854    /// whose ids are returned from `build`) are destroyed automatically
855    /// by the framework's rebuild path and do not need this call.
856    ///
857    /// If an overlay currently references `id` as its content, the
858    /// overlay is dismissed first so the manager does not retain a
859    /// stale content reference.
860    pub fn destroy_subtree(&mut self, id: WidgetId) {
861        let overlay_id = self.tree.overlay_manager().find_by_content(id);
862        if let Some(overlay_id) = overlay_id {
863            self.tree.dismiss_overlay(overlay_id);
864        }
865        self.tree.destroy_subtree(id);
866    }
867
868    /// Apply a `HandlerSet` to the composite widget being built (self).
869    /// This transfers attached event handlers, focusable flag, cursor, etc.
870    /// to the widget's arena node, replacing `event()` and `is_focusable()` overrides.
871    pub fn apply_self_handlers(&mut self, handler_set: crate::widget_builder::HandlerSet) {
872        let id = self.self_id();
873        self.tree.apply_self_handler_set(id, handler_set);
874    }
875
876    /// Move keyboard focus to `id`. Mirrors
877    /// `EventContext::request_focus` for use during `build()` — e.g.
878    /// when a composing widget pre-builds an editor and needs focus to
879    /// land on it as soon as the subtree is wired in.
880    pub fn focus(&mut self, id: WidgetId) {
881        self.tree.focus(id);
882    }
883
884    /// Find the first focusable widget within the subtree rooted at
885    /// `root` in depth-first order. Returns `None` when the subtree has
886    /// no focusable descendant or `root` is not in the arena.
887    pub fn first_focusable_descendant(&self, root: WidgetId) -> Option<WidgetId> {
888        self.tree.first_focusable_descendant(root)
889    }
890
891    /// Move keyboard focus **into** the subtree rooted at `id`: its first
892    /// focusable descendant in tab order, or `id` itself when it is the only
893    /// focusable thing there. Returns whether focus ended up inside `id`.
894    ///
895    /// The build-time twin of
896    /// [`EventContext::request_focus_into`](crate::widget::EventContext::request_focus_into),
897    /// and safe here for the same reason [`focus`](Self::focus) is: `add` builds
898    /// a child's whole subtree synchronously, so by the time a composing widget
899    /// holds a child's id the focusable descendants of that child already exist.
900    ///
901    /// **Idempotent, and that is the point.** `build` runs again on every
902    /// rebuild, so a bare `focus` here would drag focus back into this subtree
903    /// every time the owner rebuilt for an unrelated reason — a table body pane
904    /// rebuilds on selection, on filtering and on scroll. This is a no-op while
905    /// focus already sits inside `id`, so it expresses "focus belongs in here"
906    /// rather than "focus here now".
907    ///
908    /// A subtree with nothing focusable leaves focus exactly where it was: an
909    /// empty region never traps it.
910    ///
911    /// ⚠ **Ancestor-chain side effects do not run**, and that is a property of
912    /// focusing from `build` at all, not of this method — [`focus`](Self::focus)
913    /// has it too. A node added during `build` is not parented until the build
914    /// that produced it *returns*, so at this moment `id`'s chain stops at
915    /// whatever the caller has already inserted: `focus_within` signals on
916    /// enclosing nodes never flip, and `scroll_focused_into_view` finds no
917    /// scroll container to reveal the target in. Everything **below** `id` is
918    /// linked (children are parented as each is inserted), so the walk that
919    /// picks the focusable descendant, and every later key dispatch — which
920    /// happens after the pass, on a whole tree — are unaffected.
921    ///
922    /// Reach for [`EventContext::request_focus_into`](crate::widget::EventContext::request_focus_into)
923    /// where the difference matters: it is queued and drained after dispatch,
924    /// against a complete tree.
925    pub fn focus_into(&mut self, id: WidgetId) -> bool {
926        if let Some(focused) = self.tree.focused()
927            && (focused == id || self.tree.is_descendant_of(focused, id))
928        {
929            return true;
930        }
931        match self.tree.first_focusable_descendant(id) {
932            Some(target) => {
933                self.tree.focus(target);
934                true
935            }
936            None => false,
937        }
938    }
939
940    // --- Actions & shortcuts ---
941
942    /// Attach an [`Action`](crate::action::Action) to the widget being
943    /// built. Actions are consulted during intent dispatch as the
944    /// framework walks source-widget → root; the first matching,
945    /// enabled action wins (subject to the `IntentResponse` returned
946    /// by its handler).
947    ///
948    /// Actions are cleared on rebuild, mirroring event handlers.
949    pub fn register_action(&mut self, action: crate::action::Action) {
950        let id = self.self_id();
951        self.tree.push_action(id, action);
952    }
953
954    /// Declare that the widget being built **edits text**.
955    ///
956    /// Every text widget should call this. It is what lets an application take
957    /// a text chord — `Ctrl+Z`, `Ctrl+C` — for itself without silently breaking
958    /// the widget it took it from: the host asks
959    /// [`focused_text_surface`](crate::widget_tree::WidgetTree::focused_text_surface)
960    /// and either drives this surface or steps aside so the widget keeps its own
961    /// keys. See [`crate::text_surface`] for the whole argument.
962    ///
963    /// Owned by the registering widget and torn down on its rebuild or destroy,
964    /// like [`register_action_global`](Self::register_action_global). Calling it
965    /// twice from one widget re-points rather than duplicating, so a rebuild
966    /// that hands over a fresh handle is correct.
967    pub fn register_text_surface(
968        &mut self,
969        surface: std::rc::Rc<dyn crate::text_surface::TextSurface>,
970    ) {
971        let id = self.self_id();
972        self.tree.push_text_surface(id, surface);
973    }
974
975    /// A cloneable view of this tree's registered text surfaces.
976    ///
977    /// Take it once, during `build`, and hold it: a view-model refreshed from a
978    /// frame tick has no `&WidgetTree` to consult, and that is exactly when it
979    /// needs to know whether the caret is in a text widget.
980    pub fn text_surfaces(&self) -> crate::text_surface::TextSurfaces {
981        self.tree.text_surfaces()
982    }
983
984    /// Register a **window-global** [`Action`](crate::action::Action), owned by
985    /// the widget being built. Unlike [`register_action`](Self::register_action)
986    /// — which only fires when this widget is on the intent's source→root walk —
987    /// a global action is consulted as a dispatch *fallback*, so it is reachable
988    /// no matter where the intent originated: a menu-bar dropdown (which renders
989    /// in an overlay, not under the registering widget), deep content, or a
990    /// global shortcut anchored at the root when nothing is focused.
991    ///
992    /// This is the action-side counterpart to
993    /// [`register_shortcut_global`](Self::register_shortcut_global): use it for
994    /// app-wide commands (`app.save`, `view.toggle_sidebar`) whose handler lives
995    /// at the app root but whose triggers (menu, toolbar, shortcut) are scattered
996    /// across the tree and chrome. Ownership applies: the action is torn down
997    /// when this widget rebuilds or is destroyed.
998    pub fn register_action_global(&mut self, action: crate::action::Action) {
999        let id = self.self_id();
1000        self.tree.push_global_action(id, action);
1001    }
1002
1003    /// Register a [`Shortcut`](crate::shortcut::Shortcut) in the
1004    /// tree's registry, owned by the widget being built.
1005    ///
1006    /// If the shortcut builder left `scope` at the default
1007    /// ([`ShortcutScope::Global`](crate::shortcut::ShortcutScope::Global)),
1008    /// this method rewrites it to `Scoped(self_id)` so the shortcut
1009    /// only fires when focus is inside the registering widget's
1010    /// subtree — the ergonomic default for widget-declared shortcuts.
1011    /// Callers that want an explicit global shortcut should use
1012    /// [`BuildContext::register_shortcut_global`] instead; callers
1013    /// that want to scope to a specific child should set
1014    /// `.scope_to(child_id)` on the builder themselves.
1015    ///
1016    /// Ownership: the shortcut is removed from the registry when the
1017    /// widget is destroyed or rebuilt. User overrides survive across
1018    /// rebuilds (graveyard semantics).
1019    pub fn register_shortcut(&mut self, mut shortcut: crate::shortcut::Shortcut) {
1020        let id = self.self_id();
1021        if shortcut.scope == crate::shortcut::ShortcutScope::Global {
1022            shortcut.scope = crate::shortcut::ShortcutScope::Scoped(id);
1023        }
1024        self.tree
1025            .shortcut_registry_mut()
1026            .register_owned(shortcut, id);
1027    }
1028
1029    /// Register a [`Shortcut`](crate::shortcut::Shortcut) with
1030    /// explicit global scope, owned by the widget being built. Unlike
1031    /// [`BuildContext::register_shortcut`], this does not rewrite the
1032    /// scope — the shortcut fires regardless of focus position.
1033    ///
1034    /// Ownership still applies: the shortcut is torn down when this
1035    /// widget goes away.
1036    pub fn register_shortcut_global(&mut self, mut shortcut: crate::shortcut::Shortcut) {
1037        let id = self.self_id();
1038        shortcut.scope = crate::shortcut::ShortcutScope::Global;
1039        self.tree
1040            .shortcut_registry_mut()
1041            .register_owned(shortcut, id);
1042    }
1043
1044    /// Pre-declare shortcuts on behalf of a not-yet-mounted child
1045    /// (e.g. a `Switcher` walking its `Pending` slots' static
1046    /// declarations before they're inserted). Each shortcut is owned
1047    /// by the *calling* widget and its declared scope is preserved
1048    /// as-is — unlike [`register_shortcut`](Self::register_shortcut),
1049    /// no rewrite from `Global` to `Scoped(self)` happens, because
1050    /// the child intended its own scope.
1051    ///
1052    /// When the child is eventually mounted, the framework's
1053    /// insert-time walk of `Widget::declare_shortcuts` re-registers
1054    /// the same ids owned by the *child*; the registry's idempotent
1055    /// upsert moves ownership cleanly. If the child never mounts, the
1056    /// pre-declared entries stay alive (owned by the parent) so
1057    /// settings UIs still see them, and they get torn down when the
1058    /// parent goes away.
1059    pub fn register_pending_shortcuts(
1060        &mut self,
1061        shortcuts: impl IntoIterator<Item = crate::shortcut::Shortcut>,
1062    ) {
1063        let id = self.self_id();
1064        let registry = self.tree.shortcut_registry_mut();
1065        for shortcut in shortcuts {
1066            registry.register_owned(shortcut, id);
1067        }
1068    }
1069
1070    /// Read-through access to the tree's shortcut registry. Consumers
1071    /// (menus, tooltips) look up the effective keystroke for a given
1072    /// id here, and observe
1073    /// [`ShortcutRegistry::version`](crate::shortcut::ShortcutRegistry::version)
1074    /// to refresh when the user rebinds.
1075    pub fn shortcut_registry(&self) -> &crate::shortcut::ShortcutRegistry {
1076        self.tree.shortcut_registry()
1077    }
1078
1079    /// Effective view of a shortcut by id, merged with any user
1080    /// override. Returns `None` when no default has been registered
1081    /// for `id`. Typical caller pattern: call from `paint()` so
1082    /// late-registered shortcuts are still picked up without a
1083    /// dedicated build-phase query.
1084    pub fn effective_shortcut<'b>(
1085        &'b self,
1086        id: &str,
1087    ) -> Option<crate::shortcut::EffectiveShortcut<'b>> {
1088        self.shortcut_registry().effective(id)
1089    }
1090
1091    /// Convenience accessor for the reactive version signal. Widgets
1092    /// that render shortcut-derived state (menu labels, tooltips)
1093    /// observe this so the UI refreshes when the user rebinds or a
1094    /// new shortcut is registered.
1095    pub fn shortcut_version(&self) -> &Signal<u64> {
1096        self.shortcut_registry().version()
1097    }
1098
1099    /// A reactive, **per-id** handle to a shortcut's effective primary
1100    /// keystroke — the granular alternative to [`Self::shortcut_version`].
1101    /// Bind this to render one shortcut's accelerator as a *leaf* value
1102    /// (a menu item's trailing label, a tooltip) that refreshes in place
1103    /// when the user rebinds *that* id, without observing — and rebuilding
1104    /// on — every unrelated registry mutation. The signal is created on
1105    /// first request, seeded with the current value, and kept live by the
1106    /// registry across register / unregister / rebind of that id.
1107    pub fn effective_shortcut_signal(
1108        &mut self,
1109        id: &'static str,
1110    ) -> Signal<Option<crate::shortcut::KeyStroke>> {
1111        self.tree
1112            .shortcut_registry_mut()
1113            .effective_primary_signal(id)
1114    }
1115
1116    /// Apply a `HandlerSet` to a child widget created during this build.
1117    /// Use this to attach event handlers to children without wrapping them
1118    /// in `WidgetWithHandlers`.
1119    pub fn apply_handlers(
1120        &mut self,
1121        id: crate::widget_id::WidgetId,
1122        handler_set: crate::widget_builder::HandlerSet,
1123    ) {
1124        // A composing parent attaches handlers to a child — from the
1125        // child's perspective these are external and must survive the
1126        // child's own rebuilds.
1127        self.tree.apply_external_handler_set(id, handler_set);
1128    }
1129
1130    /// Wire an accessibility `labelled_by` relation from an already-mounted
1131    /// child (`id`) to its label (`label_id`), so assistive tech announces the
1132    /// field by its visible label (WCAG 3.3.2 / EN 301 549 11.5.2.7). Unlike
1133    /// the `.access_labelled_by(..)` builder method, this operates *after* the
1134    /// child is mounted (so a container like `FormLayout` can pair a label and
1135    /// a boxed field once both ids are resolved) and preserves any
1136    /// accessibility overrides the child already carries.
1137    pub fn access_labelled_by(
1138        &mut self,
1139        id: crate::widget_id::WidgetId,
1140        label_id: crate::widget_id::WidgetId,
1141    ) {
1142        self.tree.push_access_labelled_by(id, label_id);
1143    }
1144
1145    /// Wire an accessibility `described_by` relation from an already-mounted
1146    /// child (`id`) to a description/error node (`target_id`) — the
1147    /// post-mount, override-preserving counterpart of the
1148    /// `.access_described_by(..)` builder method (WCAG 3.3.1).
1149    pub fn access_described_by(
1150        &mut self,
1151        id: crate::widget_id::WidgetId,
1152        target_id: crate::widget_id::WidgetId,
1153    ) {
1154        self.tree.push_access_described_by(id, target_id);
1155    }
1156
1157    /// The id this subscription should carry: the one the previous build used at this
1158    /// same position, or a fresh one.
1159    ///
1160    /// ⚠ **Position is the whole matching rule**, and it is deliberate. The alternative
1161    /// — matching on the origin — cannot be written here: `origin` reaches the adapter
1162    /// as `Box<dyn Any>`, with no `Eq` and no `Hash` to compare it by, and requiring
1163    /// either would change every `EventSource` in existence. Position is stable for the
1164    /// shape widgets actually have, where `build()` runs the same subscribe calls in the
1165    /// same order every time.
1166    ///
1167    /// What a widget that subscribes *conditionally* gets: if the origin at position N
1168    /// differs between two builds, an event still in flight from the old origin is
1169    /// delivered to the new build's callback rather than being dropped. That is safe by
1170    /// construction rather than by luck — an app registers exactly one `EventSource`, so
1171    /// every subscription in the tree shares one origin type and one event type, and the
1172    /// payload downcast cannot mismatch. The callback receives the whole event and can
1173    /// read its origin, which is what `Origin::LongOperation(..)` handlers already do.
1174    fn next_subscription_id(
1175        &self,
1176        app_context: &crate::event_source::TreeAppContext,
1177    ) -> SubscriptionId {
1178        // `subscription_handles` is pushed to once per subscribe call and starts empty
1179        // for each build, so its length *is* this call's position within the build.
1180        self.reusable_sub_ids
1181            .get(self.subscription_handles.len())
1182            .copied()
1183            .unwrap_or_else(|| app_context.allocate_subscription_id())
1184    }
1185
1186    /// Subscribe to events from the registered application event source.
1187    /// The callback runs on the UI thread when the source publishes an
1188    /// event with a matching origin.
1189    ///
1190    /// The subscription is scoped to the current widget's lifetime: when
1191    /// the widget is rebuilt or destroyed, the framework drops the source
1192    /// handle (unregistering from the source) and removes the UI-side
1193    /// callback.
1194    ///
1195    /// It is scoped to the window it was registered from as well. A closing window's
1196    /// tree is dropped wholesale, with no per-widget destroy pass, so teksilo-app calls
1197    /// [`TreeAppContext::purge_subscriptions_for_window`](crate::event_source::TreeAppContext::purge_subscriptions_for_window)
1198    /// to drop the callbacks that window installed. A registration from a windowless
1199    /// tree (headless / tests) records no window, and only the per-widget path above
1200    /// removes such a callback.
1201    ///
1202    /// # Panics
1203    ///
1204    /// Panics if no event source has been registered on the
1205    /// `TeksiloAppBuilder`. In debug builds, also asserts that the `Origin`
1206    /// and `Event` types match the registered source.
1207    pub fn subscribe_event<O, E, F>(&mut self, origin: O, callback: F)
1208    where
1209        O: 'static,
1210        E: 'static,
1211        F: Fn(&E) + 'static,
1212    {
1213        use std::any::{Any, TypeId};
1214        use std::rc::Rc;
1215        use std::sync::Arc;
1216
1217        // Recorded so `TreeAppContext::purge_subscriptions_for_window` can drop this
1218        // entry when the window closes. A closing window's tree is dropped wholesale,
1219        // with no per-widget destroy pass, so nothing else ever reaches the entry and
1220        // the callback (plus everything it captured) would stay live for the rest of
1221        // the process. `None` from a windowless tree (headless / tests), which no
1222        // window purge touches. Mirrors `subscribe_event_with_ctx` below.
1223        let window_id = self.window().map(|w| w.id());
1224
1225        let app_context = self.tree.app_context.clone();
1226
1227        let adapter = app_context.event_source.as_ref().expect(
1228            "BuildContext::subscribe_event called but no event source was registered \
1229             on TeksiloAppBuilder. Call .event_source(source) on the builder first.",
1230        );
1231
1232        debug_assert_eq!(
1233            adapter.origin_type,
1234            TypeId::of::<O>(),
1235            "subscribe_event origin type mismatch: source uses {}, subscribe call used {}",
1236            adapter.origin_type_name,
1237            std::any::type_name::<O>(),
1238        );
1239        debug_assert_eq!(
1240            adapter.event_type,
1241            TypeId::of::<E>(),
1242            "subscribe_event event type mismatch: source uses {}, subscribe call used {}",
1243            adapter.event_type_name,
1244            std::any::type_name::<E>(),
1245        );
1246
1247        let sub_id = self.next_subscription_id(&app_context);
1248
1249        // The UI-side callback that runs after an event posted from the
1250        // source thread is delivered back to the UI thread. It downcasts
1251        // the type-erased payload back to `&E` and invokes the user's `F`.
1252        let stored_callback: Rc<dyn Fn(&dyn Any)> = Rc::new(move |event_any| {
1253            let event = event_any
1254                .downcast_ref::<E>()
1255                .expect("subscription event downcast failed — framework bug");
1256            callback(event);
1257        });
1258        app_context
1259            .subscription_callbacks
1260            .borrow_mut()
1261            .insert(sub_id, (window_id, stored_callback));
1262
1263        // Build the wrapper that the source will invoke from its
1264        // publisher thread. It carries only the sub_id (Copy) and an
1265        // Arc-clone of the poster (Send + Sync), boxes the typed event
1266        // as Any+Send, and posts an AppEvent::SubscriptionEvent through
1267        // the proxy. Tests that run without a registered poster post
1268        // events into a test queue and dispatch them back into the tree
1269        // via `tree.app_context().dispatch_subscription_event`.
1270        let poster = app_context
1271            .poster
1272            .as_ref()
1273            .expect(
1274                "BuildContext::subscribe_event called but no AppEventPoster \
1275                 is installed on the tree. teksilo-app installs one when an \
1276                 event source is registered on the builder; tests must \
1277                 supply a TestPoster via TreeAppContext::with_source_and_poster.",
1278            )
1279            .clone();
1280        let wrapper: Arc<dyn Fn(Box<dyn Any + Send>) + Send + Sync> =
1281            Arc::new(move |erased_event| {
1282                poster.post_subscription_event(sub_id, erased_event);
1283            });
1284
1285        let handle = (adapter.subscribe_fn)(Box::new(origin), wrapper);
1286        self.subscription_handles.push((sub_id, handle));
1287    }
1288
1289    /// Like [`subscribe_event`](Self::subscribe_event), but the UI-side
1290    /// callback additionally receives a fresh
1291    /// [`EventContext`](crate::widget::EventContext) bound to this widget's
1292    /// window. That lets it react to a backend event *imperatively* — update /
1293    /// replace / dismiss a toast, present a modal, `send_intent`, navigate —
1294    /// none of which a plain (context-free) `subscribe_event` callback can do
1295    /// (it can only poke `Signal`s).
1296    ///
1297    /// This is the supported bridge for **long-operation progress**: a Qleany
1298    /// `Origin::LongOperation(Progress | Completed | Cancelled | Failed)` event
1299    /// crosses from the operation's background thread to the UI thread and the
1300    /// callback drives an evolving progress toast (percentage in the body, a
1301    /// Cancel action, a success/error replacement on completion) — see the
1302    /// `toast_demo` example.
1303    ///
1304    /// The event is delivered on the UI thread through the same
1305    /// `AppEvent::SubscriptionEvent` path as `subscribe_event`; teksilo-app
1306    /// mints the `EventContext` from this widget's window tree just before the
1307    /// call (mirroring `teksilo-async`'s `spawn_local_with` completion path).
1308    /// The subscription is torn down with the widget, exactly like
1309    /// `subscribe_event`.
1310    ///
1311    /// The `<O, E>` type match against the registered event source is a
1312    /// `debug_assert` (as in [`subscribe_event`](Self::subscribe_event)); a
1313    /// mismatched call site in a release build is not caught here but panics
1314    /// later at the payload downcast.
1315    ///
1316    /// Registering from a windowless tree (headless / tests) is allowed but
1317    /// records `None` for the window — the app-side router then has no tree to
1318    /// mint an `EventContext` from and cannot deliver it, so such a subscription
1319    /// never fires in a running app. Ordinary application widgets always have a
1320    /// window; headless code that wants to observe events should use
1321    /// [`subscribe_event`](Self::subscribe_event) and drive `Signal`s instead.
1322    pub fn subscribe_event_with_ctx<O, E, F>(&mut self, origin: O, callback: F)
1323    where
1324        O: 'static,
1325        E: 'static,
1326        F: Fn(&E, &mut crate::widget::EventContext) + 'static,
1327    {
1328        use std::any::{Any, TypeId};
1329        use std::rc::Rc;
1330        use std::sync::Arc;
1331
1332        let window_id = self.window().map(|w| w.id());
1333
1334        let app_context = self.tree.app_context.clone();
1335
1336        let adapter = app_context.event_source.as_ref().expect(
1337            "BuildContext::subscribe_event_with_ctx called but no event source was registered \
1338             on TeksiloAppBuilder. Call .event_source(source) on the builder first.",
1339        );
1340
1341        debug_assert_eq!(
1342            adapter.origin_type,
1343            TypeId::of::<O>(),
1344            "subscribe_event_with_ctx origin type mismatch: source uses {}, subscribe call used {}",
1345            adapter.origin_type_name,
1346            std::any::type_name::<O>(),
1347        );
1348        debug_assert_eq!(
1349            adapter.event_type,
1350            TypeId::of::<E>(),
1351            "subscribe_event_with_ctx event type mismatch: source uses {}, subscribe call used {}",
1352            adapter.event_type_name,
1353            std::any::type_name::<E>(),
1354        );
1355
1356        // Re-used across this widget's rebuilds exactly as in `subscribe_event` — the
1357        // context-bearing path keeps its callbacks in a second map but crosses the very
1358        // same queue, so it loses in-flight events the very same way. See
1359        // [`Self::next_subscription_id`].
1360        let sub_id = self.next_subscription_id(&app_context);
1361
1362        // The UI-side callback, invoked after an event posted from the source
1363        // thread is delivered back to the UI thread and a fresh `EventContext`
1364        // has been minted. Downcasts the type-erased payload back to `&E` and
1365        // forwards it plus the context to the user's `F`. Stored behind `Rc` so
1366        // dispatch can drop the map borrow before invoking it (re-entrancy).
1367        let stored_callback: Rc<dyn Fn(&dyn Any, &mut crate::widget::EventContext)> =
1368            Rc::new(move |event_any, ctx| {
1369                let event = event_any
1370                    .downcast_ref::<E>()
1371                    .expect("subscription event downcast failed — framework bug");
1372                callback(event, ctx);
1373            });
1374        app_context
1375            .subscription_ctx_callbacks
1376            .borrow_mut()
1377            .insert(sub_id, (window_id, stored_callback));
1378
1379        // Same publisher-thread wrapper as `subscribe_event`: carry only the
1380        // sub_id (Copy) + an Arc-clone of the poster, box the typed event, and
1381        // post an `AppEvent::SubscriptionEvent`. The dispatch side (teksilo-app)
1382        // routes context-bearing sub_ids through the fresh-`EventContext` path.
1383        let poster = app_context
1384            .poster
1385            .as_ref()
1386            .expect(
1387                "BuildContext::subscribe_event_with_ctx called but no AppEventPoster \
1388                 is installed on the tree. teksilo-app installs one when an \
1389                 event source is registered on the builder.",
1390            )
1391            .clone();
1392        let wrapper: Arc<dyn Fn(Box<dyn Any + Send>) + Send + Sync> =
1393            Arc::new(move |erased_event| {
1394                poster.post_subscription_event(sub_id, erased_event);
1395            });
1396
1397        let handle = (adapter.subscribe_fn)(Box::new(origin), wrapper);
1398        self.subscription_handles.push((sub_id, handle));
1399    }
1400}
1401
1402#[cfg(test)]
1403mod effect_tests {
1404    use super::*;
1405    use crate::widget::{LayoutContext, Widget};
1406    use crate::widget_id::WidgetId;
1407    use crate::widget_tree::WidgetTree;
1408    use teksilo_canvas::SizeProposal;
1409
1410    /// A leaf widget that registers an effect on one signal to mirror its
1411    /// value into another. Produces no children.
1412    #[derive(Debug)]
1413    struct LeafWithEffect {
1414        source: Signal<i32>,
1415        mirror: Signal<i32>,
1416    }
1417
1418    impl Widget for LeafWithEffect {
1419        fn build(&mut self, ctx: &mut BuildContext) -> Vec<WidgetId> {
1420            let mirror = self.mirror.clone();
1421            ctx.effect(&self.source, move |v| mirror.set(*v));
1422            Vec::new()
1423        }
1424
1425        fn layout_response(
1426            &self,
1427            proposal: SizeProposal,
1428            _ctx: &LayoutContext,
1429        ) -> crate::widget::LayoutResponse {
1430            proposal.resolve(0.0, 0.0).into()
1431        }
1432    }
1433
1434    /// A widget that observes the per-frame tick signal and accumulates the
1435    /// deltas it receives into a shared counter, so a test can verify both
1436    /// that the tick fires at all and that the delta value is non-zero.
1437    #[derive(Debug)]
1438    struct FrameTickListener {
1439        ticks: Signal<u32>,
1440        last_delta: Signal<f32>,
1441    }
1442
1443    impl Widget for FrameTickListener {
1444        fn build(&mut self, ctx: &mut BuildContext) -> Vec<WidgetId> {
1445            let ticks = self.ticks.clone();
1446            let last_delta = self.last_delta.clone();
1447            let tick = ctx.frame_tick();
1448            ctx.effect(&tick, move |delta| {
1449                ticks.set(ticks.get() + 1);
1450                last_delta.set(*delta);
1451            });
1452            Vec::new()
1453        }
1454
1455        fn layout_response(
1456            &self,
1457            proposal: SizeProposal,
1458            _ctx: &LayoutContext,
1459        ) -> crate::widget::LayoutResponse {
1460            proposal.resolve(0.0, 0.0).into()
1461        }
1462    }
1463
1464    #[test]
1465    fn frame_tick_stays_silent_until_explicit_request() {
1466        // The draw-when-needed contract: a widget that merely observes
1467        // frame_tick must NOT keep the tree awake. Only an explicit
1468        // `request_frame()` call pumps a tick.
1469        let mut tree = WidgetTree::new();
1470        let ticks = Signal::new(0_u32);
1471        let last_delta = Signal::new(-1.0_f32);
1472        tree.add(FrameTickListener {
1473            ticks: ticks.clone(),
1474            last_delta: last_delta.clone(),
1475        });
1476
1477        // Flush the initial layout-dirty flag from widget insertion.
1478        tree.layout(teksilo_canvas::SizeProposal::exact(400.0, 300.0));
1479        assert!(
1480            !tree.frame_requested(),
1481            "observing frame_tick does not set the request flag"
1482        );
1483
1484        tree.tick_animations(std::time::Duration::from_millis(16));
1485        assert_eq!(
1486            ticks.get(),
1487            0,
1488            "an un-requested tick_animations must not fire frame_tick observers"
1489        );
1490        assert_eq!(last_delta.get(), -1.0);
1491    }
1492
1493    #[test]
1494    fn frame_tick_fires_once_per_request() {
1495        let mut tree = WidgetTree::new();
1496        let ticks = Signal::new(0_u32);
1497        let last_delta = Signal::new(-1.0_f32);
1498        let id = tree.add(FrameTickListener {
1499            ticks: ticks.clone(),
1500            last_delta: last_delta.clone(),
1501        });
1502
1503        // Flush initial layout-dirty flag so assertions reflect only
1504        // the frame-tick contract.
1505        tree.layout(teksilo_canvas::SizeProposal::exact(400.0, 300.0));
1506
1507        tree.request_frame();
1508        assert!(tree.needs_redraw(), "explicit request marks the tree dirty");
1509        assert!(tree.frame_requested());
1510
1511        tree.tick_animations(std::time::Duration::from_millis(16));
1512        assert_eq!(ticks.get(), 1);
1513        assert!((last_delta.get() - 0.016).abs() < 0.001);
1514        assert!(
1515            !tree.frame_requested(),
1516            "request flag must be cleared after the tick fired"
1517        );
1518
1519        // Second request fires exactly one more tick.
1520        tree.request_frame();
1521        tree.tick_animations(std::time::Duration::from_millis(16));
1522        assert_eq!(ticks.get(), 2);
1523
1524        // Without a request, further ticks silently advance time.
1525        tree.tick_animations(std::time::Duration::from_millis(16));
1526        assert_eq!(ticks.get(), 2);
1527
1528        tree.destroy_subtree(id);
1529        tree.request_frame();
1530        tree.tick_animations(std::time::Duration::from_millis(16));
1531        assert_eq!(
1532            ticks.get(),
1533            2,
1534            "destroyed widget's observer must not resurrect"
1535        );
1536    }
1537
1538    #[test]
1539    fn frame_tick_delta_clamped_against_huge_pauses() {
1540        let mut tree = WidgetTree::new();
1541        let ticks = Signal::new(0_u32);
1542        let last_delta = Signal::new(-1.0_f32);
1543        tree.add(FrameTickListener {
1544            ticks: ticks.clone(),
1545            last_delta: last_delta.clone(),
1546        });
1547
1548        tree.request_frame();
1549        tree.tick_animations(std::time::Duration::from_secs(5));
1550        assert_eq!(ticks.get(), 1);
1551        assert!(
1552            (last_delta.get() - 0.1).abs() < 1e-4,
1553            "frame delta must clamp at 0.1s even after a multi-second pause"
1554        );
1555    }
1556
1557    #[test]
1558    fn leaf_widget_effect_fires_and_is_cleaned_up_on_destroy() {
1559        // Regression guard: before the insert_widget / add_child fix,
1560        // effect_handles for a leaf widget (Vec::new() from build()) were
1561        // dropped the moment BuildContext went out of scope, silently
1562        // unregistering the observer. After the fix, the handle is
1563        // transferred to the arena node and the effect fires on signal
1564        // changes until the widget is destroyed.
1565        let mut tree = WidgetTree::new();
1566        let source = Signal::new(0_i32);
1567        let mirror = Signal::new(0_i32);
1568
1569        let id = tree.add(LeafWithEffect {
1570            source: source.clone(),
1571            mirror: mirror.clone(),
1572        });
1573
1574        // The effect should be live after insertion.
1575        source.set(42);
1576        assert_eq!(
1577            mirror.get(),
1578            42,
1579            "leaf widget effect must survive build() and fire on signal change"
1580        );
1581
1582        source.set(7);
1583        assert_eq!(mirror.get(), 7);
1584
1585        // Destroying the widget drops its effect_handles, which in turn
1586        // drops each ObserverHandle and unregisters the observer.
1587        tree.destroy_subtree(id);
1588        source.set(100);
1589        assert_eq!(
1590            mirror.get(),
1591            7,
1592            "effect must be unregistered after widget destruction"
1593        );
1594    }
1595}
1596
1597#[cfg(test)]
1598mod focus_into_tests {
1599    use super::*;
1600    use crate::widget::{LayoutContext, Widget};
1601    use crate::widget_builder::HandlerSet;
1602    use crate::widget_id::WidgetId;
1603    use crate::widget_tree::WidgetTree;
1604    use teksilo_canvas::SizeProposal;
1605
1606    /// A leaf that is focusable when asked, so the walk has something real to
1607    /// find — or nothing at all.
1608    #[derive(Debug)]
1609    struct Leaf {
1610        focusable: bool,
1611    }
1612
1613    impl Widget for Leaf {
1614        fn build(&mut self, ctx: &mut BuildContext) -> Vec<WidgetId> {
1615            if self.focusable {
1616                ctx.apply_self_handlers(HandlerSet::new().focusable(true));
1617            }
1618            Vec::new()
1619        }
1620        fn layout_response(
1621            &self,
1622            proposal: SizeProposal,
1623            _ctx: &LayoutContext,
1624        ) -> crate::widget::LayoutResponse {
1625            proposal.resolve(10.0, 10.0).into()
1626        }
1627    }
1628
1629    /// Holds `focusable` focusable leaves and publishes their ids.
1630    #[derive(Debug)]
1631    struct Panel {
1632        focusable: usize,
1633        leaves: Signal<Vec<WidgetId>>,
1634    }
1635
1636    impl Widget for Panel {
1637        fn build(&mut self, ctx: &mut BuildContext) -> Vec<WidgetId> {
1638            let kids: Vec<WidgetId> = (0..2)
1639                .map(|i| {
1640                    ctx.add(Leaf {
1641                        focusable: i < self.focusable,
1642                    })
1643                })
1644                .collect();
1645            self.leaves.set(kids.clone());
1646            kids
1647        }
1648        fn layout_response(
1649            &self,
1650            proposal: SizeProposal,
1651            _ctx: &LayoutContext,
1652        ) -> crate::widget::LayoutResponse {
1653            proposal.resolve(10.0, 10.0).into()
1654        }
1655    }
1656
1657    /// Calls `focus_into(panel)` on every one of *its own* builds, which is how
1658    /// a composing widget uses it. Rebuilt on demand through `tick` — and
1659    /// rebuilding it leaves the panel and its leaves alive, which is the whole
1660    /// point: that is the situation the idempotence has to survive.
1661    #[derive(Debug)]
1662    struct Driver {
1663        panel: Signal<Option<WidgetId>>,
1664        tick: Signal<u64>,
1665        moved: Signal<bool>,
1666    }
1667
1668    impl Widget for Driver {
1669        fn build(&mut self, ctx: &mut BuildContext) -> Vec<WidgetId> {
1670            self.tick.bind_to(
1671                ctx.self_id(),
1672                ctx.binding_registry(),
1673                crate::binding::BindingLevel::Rebuild,
1674            );
1675            if let Some(panel) = self.panel.get() {
1676                let moved = ctx.focus_into(panel);
1677                self.moved.set(moved);
1678            }
1679            Vec::new()
1680        }
1681        fn layout_response(
1682            &self,
1683            proposal: SizeProposal,
1684            _ctx: &LayoutContext,
1685        ) -> crate::widget::LayoutResponse {
1686            proposal.resolve(0.0, 0.0).into()
1687        }
1688    }
1689
1690    struct Probe {
1691        tree: WidgetTree,
1692        leaves: Vec<WidgetId>,
1693        tick: Signal<u64>,
1694        moved: Signal<bool>,
1695    }
1696
1697    impl Probe {
1698        fn rebuild_driver(&mut self) {
1699            self.tick.set(self.tick.get() + 1);
1700            self.tree.layout(SizeProposal::exact(100.0, 100.0));
1701        }
1702    }
1703
1704    /// A panel with `focusable` focusable leaves, plus a sibling driver that
1705    /// calls `focus_into` on it from `build`. `outside` is focusable and lives
1706    /// outside the panel, so "focus did not move" is observable.
1707    fn probe(focusable: usize) -> (Probe, WidgetId) {
1708        let leaves = Signal::new(Vec::new());
1709        let panel_id = Signal::new(None);
1710        let tick = Signal::new(0_u64);
1711        let moved = Signal::new(false);
1712
1713        let mut tree = WidgetTree::new();
1714        let outside = tree.add(Leaf { focusable: true });
1715        let panel = tree.add(Panel {
1716            focusable,
1717            leaves: leaves.clone(),
1718        });
1719        panel_id.set(Some(panel));
1720        tree.add(Driver {
1721            panel: panel_id,
1722            tick: tick.clone(),
1723            moved: moved.clone(),
1724        });
1725        tree.layout(SizeProposal::exact(100.0, 100.0));
1726        (
1727            Probe {
1728                tree,
1729                leaves: leaves.get(),
1730                tick,
1731                moved,
1732            },
1733            outside,
1734        )
1735    }
1736
1737    /// It lands on the first focusable descendant, not on the container.
1738    #[test]
1739    fn focus_into_lands_on_the_first_focusable_descendant() {
1740        let (p, _) = probe(2);
1741        assert!(p.moved.get());
1742        assert_eq!(p.tree.focused(), Some(p.leaves[0]));
1743    }
1744
1745    /// **It is a no-op while focus is already inside** — the property that lets
1746    /// it be called from `build`, which re-runs on every rebuild. A bare
1747    /// `focus` on the first focusable descendant would drag focus back to the
1748    /// first field every time the caller rebuilt for an unrelated reason, which
1749    /// mid-edit is the caret jumping to the start of the line.
1750    #[test]
1751    fn focus_into_leaves_focus_alone_when_it_is_already_inside() {
1752        let (mut p, _) = probe(2);
1753        p.tree.focus(p.leaves[1]);
1754        p.rebuild_driver();
1755        assert!(p.moved.get(), "focus is inside, so the answer is still yes");
1756        assert_eq!(
1757            p.tree.focused(),
1758            Some(p.leaves[1]),
1759            "focus was dragged back to the first focusable child"
1760        );
1761    }
1762
1763    /// A subtree with nothing focusable leaves focus exactly where it was: an
1764    /// empty region never traps it, and the caller is told so.
1765    #[test]
1766    fn focus_into_an_unfocusable_subtree_moves_nothing() {
1767        let (mut p, outside) = probe(0);
1768        p.tree.focus(outside);
1769        p.rebuild_driver();
1770        assert!(!p.moved.get());
1771        assert_eq!(p.tree.focused(), Some(outside));
1772    }
1773}