-
Notifications
You must be signed in to change notification settings - Fork 20
Expand file tree
/
Copy patheslint.config.js
More file actions
155 lines (147 loc) · 5.46 KB
/
Copy patheslint.config.js
File metadata and controls
155 lines (147 loc) · 5.46 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
// @ts-check
import tseslint from 'typescript-eslint';
import prettierConfig from 'eslint-config-prettier';
import headersPlugin from 'eslint-plugin-headers';
import simpleImportSort from 'eslint-plugin-simple-import-sort';
const NO_DIRECT_FETCH_MESSAGE =
"Don't call fetch() directly — use fetchAuthenticated() (credentialed requests) or " +
'fetchAnonymous() (credential-free requests) from @/core/server/fetch.ts, ' +
'so proxy and TLS configuration are always applied.';
export default tseslint.config(
// Global ignores
{
ignores: ['dist/**', 'node_modules/**', 'coverage/**'],
},
// License header enforcement
{
files: ['src/**/*.ts'],
plugins: { headers: headersPlugin },
rules: {
'headers/header-format': ['error', {
source: 'file',
path: 'LICENSE',
blockPrefix: '\n'
}],
},
},
// Base TypeScript config for source files
{
files: ['src/**/*.ts'],
extends: [
...tseslint.configs.strictTypeChecked,
...tseslint.configs.stylisticTypeChecked,
],
plugins: {
'simple-import-sort': simpleImportSort,
},
languageOptions: {
parserOptions: {
project: './tsconfig.json',
tsconfigRootDir: import.meta.dirname,
},
},
rules: {
'simple-import-sort/imports': 'error',
'simple-import-sort/exports': 'error',
// TypeScript-specific overrides
'@typescript-eslint/no-explicit-any': 'warn',
'@typescript-eslint/no-floating-promises': 'error',
'@typescript-eslint/no-misused-promises': 'error',
'@typescript-eslint/no-unused-vars': ['error', { argsIgnorePattern: '^_', varsIgnorePattern: '^_' }],
'@typescript-eslint/consistent-type-imports': ['error', { prefer: 'type-imports', fixStyle: 'inline-type-imports' }],
'@typescript-eslint/consistent-type-definitions': 'off',
'@typescript-eslint/no-non-null-assertion': 'warn',
'@typescript-eslint/switch-exhaustiveness-check': 'error',
'@typescript-eslint/prefer-nullish-coalescing': 'off',
'@typescript-eslint/array-type': 'off',
// Allow numbers and booleans in template literals — very common in CLI output
'@typescript-eslint/restrict-template-expressions': ['error', { allowNumber: true, allowBoolean: true }],
// Downgrade unsafe rules to warn — CLI code often interacts with loosely typed APIs
'@typescript-eslint/no-unsafe-assignment': 'warn',
'@typescript-eslint/no-unsafe-member-access': 'warn',
'@typescript-eslint/no-unsafe-argument': 'warn',
'@typescript-eslint/no-unsafe-call': 'warn',
'@typescript-eslint/no-unsafe-return': 'warn',
'@typescript-eslint/no-confusing-void-expression': 'warn',
// General best practices
'no-console': 'warn',
},
},
// Telemetry/Sentry destinations are reachable only from the two modules that own the
// outbound call; the owners are exempted in the block that follows.
{
files: ['src/**/*.ts'],
rules: {
'no-restricted-imports': [
'error',
{
// Matched as a glob against the import string, so every spelling of the path is
// covered — alias, ./, ../ and deeper.
patterns: [
{
group: ['**/config-constants.ts'],
importNames: ['TELEMETRY_ENDPOINT', 'TELEMETRY_API_KEY', 'SENTRY_DSN'],
message:
'Telemetry/Sentry destinations are confined to src/core/telemetry/telemetry-events.ts and src/core/observability/sentry.ts. Gate new outbound calls on resolveTelemetryEgress() instead.',
},
],
},
],
},
},
{
files: ['src/core/telemetry/telemetry-events.ts', 'src/core/observability/sentry.ts'],
rules: {
'no-restricted-imports': 'off',
},
},
// Every outbound HTTP request must carry the resolved proxy/TLS configuration, so the
// runtime fetch is reachable only from the module that owns the wrappers (exempted below).
{
files: ['src/**/*.ts'],
rules: {
'no-restricted-syntax': [
'error',
// Bare `fetch(...)`, then every qualified form (globalThis.fetch, Bun.fetch, ...).
{ selector: "CallExpression[callee.name='fetch']", message: NO_DIRECT_FETCH_MESSAGE },
{
selector: "CallExpression[callee.type='MemberExpression'][callee.property.name='fetch']",
message: NO_DIRECT_FETCH_MESSAGE,
},
],
},
},
{
files: ['src/core/server/fetch.ts'],
rules: {
'no-restricted-syntax': 'off',
},
},
// Relaxed rules for non-shipped code (tests + build scripts)
{
files: ['tests/**/*.ts', 'build-scripts/**/*.ts'],
extends: [...tseslint.configs.recommendedTypeChecked],
plugins: {
'simple-import-sort': simpleImportSort,
},
languageOptions: {
parserOptions: {
project: './tsconfig.json',
tsconfigRootDir: import.meta.dirname,
},
},
rules: {
'simple-import-sort/imports': 'error',
'simple-import-sort/exports': 'error',
'@typescript-eslint/no-explicit-any': 'off',
'@typescript-eslint/no-unsafe-assignment': 'off',
'@typescript-eslint/no-unsafe-call': 'off',
'@typescript-eslint/no-unsafe-member-access': 'off',
'@typescript-eslint/no-floating-promises': 'error',
'@typescript-eslint/no-unused-vars': ['error', { argsIgnorePattern: '^_', varsIgnorePattern: '^_' }],
'no-console': 'off',
},
},
// Prettier must be last — disables all formatting rules
prettierConfig,
);