Skip to content

[P2][Tier-2] LiveUIAdapter.render routes through dev-only LiveUi.Tooling (audit B4) #153

Description

@ty13r

Severity: P2 (architecture boundary) · Tier-2 (Pascal owns the Renderer/Tooling contract)
Co-maintained repo (Pascal = architect).
Location: lib/ash_ui/rendering/live_ui_adapter.ex:250-261

call_live_ui_renderer actually calls LiveUi.Tooling.inspect_canonical/2. LiveUi.Tooling is dev/test-introspection only (it import Phoenix.LiveViewTest); production rendering must go through LiveUi.Renderer. available?/0 even checks that LiveUi.Renderer is loaded, then dispatches to Tooling. Currently latent (no production caller hits the adapter when the package is present), but it violates the Renderer/Tooling separation and couples Phoenix.LiveViewTest into a render path.

Fix: route the adapter's "external available" branch through LiveUi.Renderer, or delete the Tooling call and rely on the in-repo fallback.

2026-05-28 cross-repo review — see ariston-ui docs/audits/cross-repo-review-2026-05-28.md (finding B4).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions