A modal command palette: a search input over a filtered, grouped listbox. Selecting a command emits hui-select and the host decides what it means, because authorisation and side effects are server-owned.
The server owns the commands: it renders the trigger into the trigger slot and the options as light-DOM role="option" elements with a data-value, optionally wrapped in a role="group". It owns no filtering or selection logic; the element filters those options locally and emits hui-select with the chosen value so the host can run or authorise the action. The element owns the modal dialog, the highlight and the focus restore, so the server must not render its own dialog or listbox. An hx-swap that replaces the command while it is open removes the top-layer modal and its focus restore, so refresh the option set with an out-of-band swap rather than replacing the element.
Accessibility
The dialog is named by label through aria-label.
The search input is a role="combobox" with aria-expanded="true" and aria-controls pointing at the listbox.
Focus moves to the input on open and returns to the trigger on close; any element passed to show() overrides the remembered trigger.
Clicking the dimmed backdrop closes the palette, which a modal dialog does not do by itself.
When nothing matches, the role="status" empty message is shown.
Keyboard
Keyboard
Keys
Action
ArrowDown, ArrowUp
Move the highlight through the visible commands, wrapping at the ends.
Home, End
Move the highlight to the first or last visible command.
Enter
Run the highlighted command by emitting hui-select, then close.
Escape
Close the palette and restore focus to the trigger.
Printable characters
Filter the commands and hide a group once all of its items are gone.
Gotchas
The open palette is a native modal <dialog> in the top layer, so a swap that replaces it while open tears the modal down and loses the trigger focus would return to.
Its filter helper is private; the host cannot call it and must drive filtering through the search input's own events.
The palette runs nothing itself; hui-select only reports the choice, so the host performs the action and any authorisation.