AddThisFeature

Tokenized Inline Styles

Allow styles computed at runtime without letting arbitrary values escape the design system.

moderate CSS & Styling

What it adds

A constrained path for dynamically computed styles, where every value is either a design token or a number clamped to an approved range.

What your agent is told to do

5
  1. 1

    Find every place the app already sets a style value at runtime — progress widths, chart bar heights, avatar colours, drag positions, user-chosen accent colours — and sort them into two groups: values that must come from the token set, and values that are genuinely continuous numbers.

  2. 2

    For the first group, accept only token names and resolve them to values at the boundary. A caller passing a raw colour or a raw pixel value should be rejected loudly in development rather than quietly rendered.

  3. 3

    For the second group, clamp to a documented minimum and maximum and round to a sensible precision, so a percentage of 4000 or a width of 0.3847291 pixels never reaches the DOM.

  4. 4

    Treat any value that originated with a user or another tenant as untrusted. Strip anything that could terminate a declaration or introduce a new one, and never let a user-supplied string reach a URL-valued property.

  5. 5

    Do not solve this by generating a new class per distinct value. A stylesheet that grows with your data is a memory and parse cost that shows up only at scale, and it defeats the caching the app already relies on.

Edge cases it handles

7
  • A caller that passes an arbitrary hex colour or a hand-written pixel value where a token is required must be rejected, not silently accepted — otherwise the token set stops describing the app within a release or two.
  • Values that originated with a user or an external system must be sanitised before they are used, because a style value is a place markup can be smuggled in and a place a remote request can be triggered.
  • Server-rendered and client-rendered output must agree exactly on the first paint. A value rounded differently on the two sides produces a hydration mismatch and a visible flash.
  • The number of distinct generated rules must stay bounded. Styling a thousand rows with a thousand unique declarations is a cost that only appears on the largest accounts.
  • A token that is removed or renamed later must fail visibly at the point of use rather than resolving to an empty value and rendering an unstyled element.
  • Theme changes must flow through the same path. A runtime style that hardcodes a resolved colour will not follow the user into dark mode.
  • Animated values updated every frame must not go through the token resolver on each tick; resolve once and interpolate.

Definition of done

8
  • Every runtime style value is either a named token or a number clamped to a documented range.
  • Passing an off-system value where a token is required fails visibly in development.
  • User-supplied and third-party values are sanitised before they reach any style property.
  • Server and client render identical style output on first paint, with no hydration mismatch.
  • The count of distinct generated style rules does not grow with the number of records displayed.
  • Runtime-styled elements follow theme changes without being re-mounted.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.