Skip to content
← All rules
API ContractsInput validation

api-contracts/require-input-validation

Explicit route and raw boundary inputs need runtime validation; type annotations alone do not establish that incoming data is valid.

validationroutesuntrusted-input
TypeScript
app.post("/users", req => createUser(req.body));
Finding

Require validation of untrusted boundary input.

Setup

Install the package, register its plugin factory, then enable the rule.

Install the package

pnpm add -D @scruple/api-contracts

Register the plugin

In scruple.config.ts, register the factory under the api-contracts namespace used by the rule ID.

import { apiContracts } from "@scruple/api-contracts";

plugins: {
  "api-contracts": apiContracts(),
},

Enable the rule

"api-contracts/require-input-validation": "warn"
Package
@scruple/api-contracts
Default threshold
0.85
Minimum confidence
0.7

Released under the MIT License.