mirror of
https://github.com/priyanshujain/sanderling.git
synced 2026-10-02 19:17:10 +00:00
docs: correct the record that android never reports a secure field
Four places said android reports the fact for nothing and that every typed value there is redacted. The sidecar now states it, so they described the old behaviour.
This commit is contained in:
1 parent
8b4c300ad2
commit
a38b4a8047
5 files changed
+15
-15
No files matched your search
+1
-1
@@ -33,7 +33,7 @@ The trace is written incrementally. An interrupted run is complete up to the ste
|
||||
|
||||
A run types into whatever the app puts on screen, login forms included, and the trace and the model call record are both shared. So a typed value is written down as `[redacted]` whenever the target may be a credential entry: the trace action, the recent-action memory the prompt carries, the numbered candidate list, and the `state.lastAction` a spec reads (and can extract into the trace) all render it that way. The app still receives the real keystrokes; only the record is redacted, and the record still names the field that was typed into.
|
||||
|
||||
Which values that covers differs by platform, because the platforms differ in what they report. iOS and web state on every editable field whether it masks its input, so only the fields that do are redacted and the rest of the memory keeps its values. Android reports nothing: uiautomator's password attribute is dropped by the native tree mapper before the driver sees it, a password field is indistinguishable from a search box there, and so every typed value on Android is redacted.
|
||||
Which values that covers is decided per field, from what the platform says about it. iOS and web state on every editable field whether it masks its input. Android states it too, though the tree the sidecar gets from maestro does not: maestro's mapper copies a fixed attribute list off the device's view hierarchy and `password` is not on it, so the sidecar re-reads that hierarchy once per settled snapshot and puts the fact back on the text fields it can match. A field it cannot match is left unstated, and an unstated field is redacted.
|
||||
|
||||
## App state across runs
|
||||
|
||||
|
||||
@@ -84,7 +84,7 @@ Every key-value pair must match. A key means the same thing here as in the strin
|
||||
|
||||
Known attribute names are typed; you get autocomplete on `testTag`, `text`, `content-desc`, the boolean states (`clickable`, `enabled`, `focused`, `checked`, `selected`, `editable`, `secure`), and the cross-platform aliases (`identifier`, `accessibilityIdentifier`, `accessibilityText`, `accessibilityLabel`, `ariaLabel`, `contentDescription`, `label`, `testID`, `resource-id`, `class`, `className`, `elementType`, `package`, `placeholderValue`, `hintText`). Boolean state attributes accept a native `true` / `false`. Other attribute keys still type-check as a string-valued fallback so raw driver attributes remain reachable.
|
||||
|
||||
A boolean state matches only where the platform reports it. `{secure: true}` names the password entry and `{secure: false}` names an editable field that is not one, so neither value names an element that is no field at all, and neither matches anything on Android, which reports the fact for nothing.
|
||||
A boolean state matches only where the platform reports it. `{secure: true}` names the password entry and `{secure: false}` names an editable field that is not one, so neither value names an element that is no field at all. All three platforms report it; on Android a text field the sidecar cannot match against the device's own view hierarchy is left unstated and answers to neither value.
|
||||
|
||||
`clickable`, `enabled`, `focused`, `checked`, `selected` and `editable` are reported for every element, so both values of each match: `{clickable: false}` names every element that is not a tap target. They are read off the element as it stands, never off a markup attribute of the same name, so a box the user ticked answers to `{checked: true}` on a page whose markup never wrote `checked` anywhere.
|
||||
|
||||
@@ -145,7 +145,7 @@ Fields available on every element returned by `find` / `findAll`:
|
||||
| `checked` | `boolean` | Checkbox or toggle state |
|
||||
| `focused` | `boolean` | Element has input focus |
|
||||
| `selected` | `boolean` | Selection state |
|
||||
| `secure` | `boolean \| null` | Field masks what is typed into it; `null` where the platform does not report it (Android never does) |
|
||||
| `secure` | `boolean \| null` | Field masks what is typed into it; `null` where the platform does not report it |
|
||||
| `bounds` | `{ left, top, right, bottom }` | Bounding box in device pixels |
|
||||
| `x` | `number` | Center X (derived from bounds) |
|
||||
| `y` | `number` | Center Y (derived from bounds) |
|
||||
|
||||
Reference in new issue
Block a user