ConfirmButton¶
Button with explicit confirmation prompt (not authorization).
| Import | from hedron import ConfirmButton |
| Distribution | hedron |
| Backend activity | No |
| Normal render mode | RenderMode.FRAGMENT |
Live demo¶
Docs simulation — not a running Hedron server. Interactive demos show a “Simulated HTMX” trace when applicable.
Minimal runnable app.py that reproduces this demo (real Hedron, not the docs simulator):
import os
from hedron import Hedron, Page, html, swap
app = Hedron(
title="ConfirmButton demo",
security="standard",
explorer="off",
session_secret=os.environ.get("HEDRON_SESSION_SECRET", "dev-only"),
)
row = app.region("confirm-row")
@app.page("/")
def home() -> Page:
return Page(
html.div(
html.div(
html.strong("Draft report"),
html.span("Row present until you confirm delete."),
),
html.button(
"Delete item",
type="button",
class_="hedron-button hedron-button-danger hedron-confirm-button",
**{
"hx-confirm": "Delete item?",
"hx-delete": "/items/1",
"hx-target": row.selector,
"hx-swap": "innerHTML",
},
),
id=row.id,
),
title="ConfirmButton",
)
@app.action("/items/1", method="DELETE", fragment_regions=(row,))
def delete():
return swap(
html.div(
html.strong("Item deleted"),
html.span("Row removed after confirm."),
role="status",
)
)
Basic use¶
Compose under Page for full documents, or return from a fragment route for HTMX swaps.
How it works¶
Phase 0.15 surface. Prefer native HTML semantics and ordinary HTTP actions.
This component can initiate or represent a backend interaction. The live documentation intercepts that interaction with JavaScript and shows the same pending, success, or replacement states without making a real request. In an application, keep the URL, authorization, validation, and returned fragment on the server; JavaScript is only progressive enhancement.
Constructor and parameters¶
ConfirmButton(label: 'str', *, confirm: 'str', type: "Literal['button', 'submit', 'reset']" = 'button', disabled: 'bool' = False, variant: "Literal['primary', 'secondary', 'danger']" = 'danger', mark: 'str | None' = None, **kwargs: 'object') -> 'None'
| Parameter | Type | Meaning |
|---|---|---|
label |
str |
Accessible label text shown to users. |
confirm |
str |
Confirmation prompt text shown before the action runs. |
type |
Literal['button', 'submit', 'reset'] |
Native button type (button, submit, or reset). Default: 'button'. |
disabled |
bool |
Whether the control is non-interactive. Default: False. |
variant |
Literal['primary', 'secondary', 'danger'] |
Visual / semantic variant for the control. Default: 'danger'. |
mark |
str | None |
Optional stable test mark (data-hedron-mark). Default: None. |
Composition and backend behavior¶
Keep ConfirmButton at the smallest semantic boundary. Fragment routes should return only
the replaced region and preserve stable target IDs across success, validation, empty,
loading, and error responses.
Mutating flows must use POST, validate CSRF, authorize on the server, re-validate typed input, and return a bounded fragment. GET remains safe and repeatable; native submit should still work without HTMX.
Accessibility¶
Keyboard and screen-reader operable; no-JS fallback required where interactive.
Security¶
Escaping and SafeUrl / TrustedHtml are framework concerns; authorization and data
exposure remain application code. Redact secrets before rendering.
Common mistakes¶
- Do not treat client-only hints (geolocation, browser storage) as authorization.
- Do not copy docs-preview JavaScript into an application server.