Skip to content
← All rules
API ContractsHTTP contracts

api-contracts/no-side-effects-in-safe-http-methods

GET, HEAD, OPTIONS, and TRACE routes should not perform requested domain mutations; incidental logging, metrics, auditing, and cache upkeep are allowed.

httpside-effectsroutes
TypeScript
app.get("/users/:id/activate", req => activateUser(req.params.id));
Finding

Disallow requested mutation through safe HTTP methods.

Setup

Install the package, register its plugin factory, then enable the rule.

Install the package

pnpm add -D @scruple/api-contracts

Register the plugin

In scruple.config.ts, register the factory under the api-contracts namespace used by the rule ID.

import { apiContracts } from "@scruple/api-contracts";

plugins: {
  "api-contracts": apiContracts(),
},

Enable the rule

"api-contracts/no-side-effects-in-safe-http-methods": "warn"
Package
@scruple/api-contracts
Default threshold
0.9
Minimum confidence
0.75

Released under the MIT License.