API ContractsHTTP contracts
api-contracts/no-side-effects-in-safe-http-methods
GET, HEAD, OPTIONS, and TRACE routes should not perform requested domain mutations; incidental logging, metrics, auditing, and cache upkeep are allowed.
01 Examples
TypeScript
app.get("/users/:id/activate", req => activateUser(req.params.id));Finding
Disallow requested mutation through safe HTTP methods.
02 Enable it
Setup
Install the package, register its plugin factory, then enable the rule.
Install the package
pnpm add -D @scruple/api-contractsRegister the plugin
In scruple.config.ts, register the factory under the api-contracts namespace used by the rule ID.
import { apiContracts } from "@scruple/api-contracts";
plugins: {
"api-contracts": apiContracts(),
},Enable the rule
"api-contracts/no-side-effects-in-safe-http-methods": "warn"- Package
@scruple/api-contracts- Default threshold
- 0.9
- Minimum confidence
- 0.75