Skip to main content

Component · Inputs

Password Input

A secure secret-entry field that masks paint, redacts Debug/semantic output, and never embeds secrets in outcomes.

Kind
widget
Input
interactive
Canvas
120×40

Live preview

Loading terminal preview.

Static terminal poster. Choose Run live to start the Rust demo.

Ghosttypassword-input/basic
Loading terminal poster…
○ loading posterNo input — rendered state only
Password Input · exact mounted Rust story

01 · Purpose

What it is for

A secure secret-entry field that masks paint, redacts Debug/semantic output, and never embeds secrets in outcomes.

Best fit: Inputs · input · widget

02 · Behavior

What the mounted story proves

  1. 01

    PasswordInput

    Representative 120×40 terminal state.

  2. 02

    Passive paint

    No keyboard or pointer action is claimed by this representative story.

  3. 03

    Evidence stays explicit

    3 covered · 8 partial · 5 missing axes.

03 · Implement

Install, then start from exact code

Install

cargo add termrock --git https://github.com/tailrocks/termrock.git --rev 5283c2acf9154d0cfcd37b1ffe821c00faf90ea2

Add TermRock once. Keep domain effects in the host application.

Minimal implementation

Exact Rust setup used by password-input/basic.

Open to load code.

04 · Adapt

Variants and composition

Variants

Use the preview Variant menu when alternate registered stories exist. Each selection mounts a fresh configuration.

Composition

Inputs · input · widget

05 · Reference

API, tokens, accessibility

API

PasswordInputOpen source ↗

Tokens

DesignSystemInspect exact story code for roles and capability projection.

Accessibility

Input contract mountedNo input claim in the representative story.

Contract

Evidence in progress3/23 axes covered

06 · Go deeper

Advanced guidance

Authored implementation guidance

Purpose. Credential and token fields that must not leak through paint (when masked), Debug, semantic scene, or outcome payloads.

When to use / when not

Use PasswordInputPrefer
Passwords, API tokens, recovery codes—
Non-secret masked demo onlyTextInput::secret paint mask
Multi-line secretsavoid — use single-line tokens or host file

Security contract

ChannelBehavior
PaintMask graphemes unless reveal policy shows plaintext
DebugRedacted (filled, policies only)
Semantic sceneLabels like password masked — never value
OutcomesNo secret strings; Submitted is a signal
ClipboardDefault paste-only; copy never embeds secret
Dropsecure_clear overwrites buffer + undo snapshots

Reveal

  • Never (default)
  • Explicit — Alt+R or reveal glyph
  • Hold — Alt+H press/release

Clipboard

  • DenyAll
  • PasteOnly (default)
  • AllowHostCopy — ClipboardCopyAllowed; host may call secret() carefully
Ownership boundary

TermRock owns reusable terminal rendering and interaction state. The host owns domain data, policy, persistence, authorization, and side effects.

Evidence status

3 covered, 8 partial, and 5 missing contract axes. Missing evidence is not a behavior claim.