Fix L7/M13/M37: badge colors, secret masking, dev-jargon hints

L7: Canceled status chip now uses 'subtle' color (neutral) instead of 'warning'
    (amber) -- distinguishing it from paused which remains amber.
M13: Proxy URL and YouTube PO-token inputs now use type="password" to mask
     credentials, matching updateToken. Proxy URLs can carry user:pass; PO tokens
     are opaque secrets.
M37: Rewrite two dev-facing hints -- youtubePlayerClient now says 'how AeroFetch
     identifies itself to YouTube' instead of citing yt-dlp internals; filename
     template says 'Controls how saved files are named' instead of 'yt-dlp output
     template'. Remaining hints (cookie browser, aria2c, etc.) were already clean.

typecheck + 242 tests + eslint + prettier green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-06-30 14:01:25 -04:00
parent 94c5723246
commit 63a327a31c
3 changed files with 8 additions and 6 deletions
+3 -3
View File
@@ -258,7 +258,7 @@ token system + shared primitives (UI/SIMP — high value, larger effort) · i18n
`style={{ color: … }}` error spans + its local `errorRowText` class. The remaining red references live in
per-component `makeStyles` classes (DownloadBar/LibraryView/QueueItem/TerminalView), not inline; migrate
those to the shared hook incrementally.*
- [ ] **M13 — Inconsistent secret-field masking.** `updateToken` uses `type="password"`; `proxy`
- [x] **M13 — Inconsistent secret-field masking.** `updateToken` uses `type="password"`; `proxy`
(may carry `user:pass@`) and `youtubePoToken` (a token) are plain-text Inputs.
- [ ] **M14 — Settings search mutates React-owned DOM.** The search toggles each card's
`el.style.display` directly; fragile (breaks if a card ever gets a conditional `style`) and
@@ -361,7 +361,7 @@ token system + shared primitives (UI/SIMP — high value, larger effort) · i18n
pending/error/canceled only, so selecting 5 rows (incl. 2 already-downloaded) shows "Download **3**
selected." The checkbox count and the button count silently disagree. **Fix:** only show checkboxes on
actionable rows, or count all selected.
- [ ] **M37 — End-user hints leak developer/internal references.** Settings hints surface dev-facing
- [x] **M37 — End-user hints leak developer/internal references.** Settings hints surface dev-facing
detail: "Requires aria2c.exe in resources/bin (see the README there)", "paste a read-only **Gitea**
token", "sent via `--extractor-args`", "breaking downloads with **403** errors", "open a locked cookie
database", and roadmap status ("automatic minting is **planned**"). These read as code comments, not
@@ -388,7 +388,7 @@ token system + shared primitives (UI/SIMP — high value, larger effort) · i18n
where a class exists elsewhere.
- [ ] **L6 — Control height mismatch.** `Select` is a fixed 32px sitting beside `size="large"`
(~40px) Input/Buttons in DownloadBar.
- [ ] **L7 — `canceled` and `paused` share the 'warning' badge color** (QueueItem) — visually
- [x] **L7 — `canceled` and `paused` share the 'warning' badge color** (QueueItem) — visually
ambiguous.
- [ ] **L8 — Index/compound list keys.** TerminalView keys log lines by array index; Settings
Diagnostics keys by `id + occurredAt` while every other list keys by `id` alone.