mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 09:55:06 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore / build (ESLint config upgrade + lint cleanup). ## What is the current behavior? `eslint-plugin-react-hooks` v5 (pulled in transitively by `eslint-config-next` v15) doesn't recognize stable `useEffectEvent`, so every effect that calls an effect-event handler needs an `eslint-disable react-hooks/exhaustive-deps` to silence a false positive. There are 30 such dead disables across Studio. ## What is the new behavior? Bumps `eslint-config-next` to v16, which pulls in `eslint-plugin-react-hooks` v7 whose `exhaustive-deps` understands `useEffectEvent`, and removes the 30 now-dead disable directives (and their orphaned explanatory comments). Supporting changes: - **Flat-config migration**: v16 is a native flat-config array (v15 was eslintrc), so `eslint-config-supabase` now spreads it directly instead of bridging through `FlatCompat`. - **React Compiler rules off**: v16 enables react-hooks v7's `recommended`, which layers the React Compiler lint rules on top of the two classic rules. These are switched off (derived dynamically from what next enables) to keep this change scoped to the `exhaustive-deps` improvement. - **Plugin-registration fallout** (v16 scopes plugin registration to a file glob rather than registering globally like FlatCompat did): stop re-registering `@typescript-eslint` (shared) and `jsx-a11y` (studio); scope our react / react-hooks / jsx-a11y rule overrides (studio, www) to v16's plugin glob so they don't error on files outside it (e.g. `.cjs`). - **Lint surface preserved**: v16's glob newly includes `.mts`/`.cts` (v15 didn't lint them), which surfaced pre-existing errors in tooling scripts. The shared config keeps the prior surface by leaving `.mts`/`.cts` unlinted; linting them is left as a separate change. - **Ratchet**: rebaselines `@tanstack/query/exhaustive-deps` 9 → 89. v15 forced next's `@babel/eslint-parser` onto `.ts` files, hiding these deps; v16 parses `.ts` with `@typescript-eslint/parser` and correctly surfaces the intentional `connectionString`-excluded-from-`queryKey` pattern. Worth a follow-up to review whether any are real cache-correctness bugs. - Drops three now-dead devDeps from `eslint-config-supabase`: `@eslint/eslintrc`, `@eslint/js`, `@typescript-eslint/eslint-plugin`. Verified locally: `turbo run lint` → 7/7 packages pass with 0 errors; Studio `lint:ratchet` passes; Prettier clean on changed files; typecheck unaffected. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Refined linting configuration and removed outdated lint suppressions across Studio. * Updated Next.js linting support and refreshed related development configuration. * Expanded lint baseline coverage for query-related code. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
125 lines
5.4 KiB
JavaScript
125 lines
5.4 KiB
JavaScript
const { defineConfig } = require('eslint/config')
|
|
const { fixupPluginRules } = require('@eslint/compat')
|
|
const barrelFiles = require('eslint-plugin-barrel-files')
|
|
const valtio = require('eslint-plugin-valtio')
|
|
// eslint-plugin-react-hook-form@0.3.1 (latest) still calls the ESLint 8
|
|
// `context.getScope()`, which ESLint 9 removed. fixupPluginRules shims the
|
|
// deprecated context methods so the rules run under flat config.
|
|
const reactHookForm = require('eslint-plugin-react-hook-form')
|
|
const supabaseConfig = require('eslint-config-supabase/next')
|
|
|
|
// Analytics SQL wire boundary — see the block below for context. Shared so the
|
|
// API/route block can re-include it (flat config replaces, not merges, a rule's
|
|
// options when blocks overlap, so the later block must carry these forward).
|
|
const ANALYTICS_SQL_RESTRICTED_SYNTAX = [
|
|
{
|
|
selector:
|
|
"CallExpression[callee.name=/^(post|get)$/][arguments.0.value='/platform/projects/{ref}/analytics/endpoints/logs.all']",
|
|
message:
|
|
'Do not call the analytics logs.all endpoint directly. Route through executeAnalyticsSql in @/data/logs/execute-analytics-sql so the SafeLogSqlFragment brand is enforced at compile time.',
|
|
},
|
|
{
|
|
selector:
|
|
"CallExpression[callee.name=/^(post|get)$/][arguments.0.value='/platform/projects/{ref}/analytics/endpoints/logs.all.otel']",
|
|
message:
|
|
'Do not call the analytics logs.all.otel endpoint directly. Route through executeAnalyticsSql in @/data/logs/execute-analytics-sql so the SafeLogSqlFragment brand is enforced at compile time.',
|
|
},
|
|
]
|
|
|
|
// Ban constructing a Supabase client at module scope in API route files. The
|
|
// TanStack server imports the entire route tree at boot (loadEntries), so a
|
|
// module-scope createClient with an env var that's unset in that environment
|
|
// (e.g. SUPABASE_URL on platform) throws on import and 500s every route — a
|
|
// runtime-only failure that's painful to catch. Construct it lazily inside the
|
|
// handler instead (see lib/api/self-hosted-admin.ts).
|
|
const NO_MODULE_SCOPE_CREATE_CLIENT = {
|
|
selector:
|
|
":matches(Program, ExportNamedDeclaration) > VariableDeclaration > VariableDeclarator > CallExpression[callee.name='createClient']",
|
|
message:
|
|
'Do not construct a Supabase client at module scope in API route files — the TanStack server evaluates every route module at boot, so a missing env var (e.g. SUPABASE_URL on platform) crashes every route. Construct it lazily inside the handler (see lib/api/self-hosted-admin.ts).',
|
|
}
|
|
|
|
module.exports = defineConfig([
|
|
{ files: ['**/*.ts', '**/*.tsx'] },
|
|
supabaseConfig,
|
|
{
|
|
files: ['**/*.{js,jsx,mjs,ts,tsx,mts,cts}'],
|
|
plugins: {
|
|
'barrel-files': barrelFiles,
|
|
valtio,
|
|
'react-hook-form': fixupPluginRules(reactHookForm),
|
|
},
|
|
rules: {
|
|
'@next/next/no-img-element': 'off',
|
|
'react/no-unescaped-entities': 'off',
|
|
'react/display-name': 'warn',
|
|
'react/no-unstable-nested-components': 'warn',
|
|
'react/jsx-key': 'error',
|
|
'no-restricted-imports': [
|
|
'error',
|
|
{
|
|
paths: [
|
|
{
|
|
name: 'components/ui/DataTable/DataTableColumn/DataTableColumnHeader',
|
|
message: 'Use TanStackTableHeadSort from ui-patterns/Table instead.',
|
|
},
|
|
],
|
|
},
|
|
],
|
|
'barrel-files/avoid-re-export-all': 'error',
|
|
'jsx-a11y/alt-text': 'warn',
|
|
'jsx-a11y/role-has-required-aria-props': 'error',
|
|
'jsx-a11y/aria-props': 'warn',
|
|
'jsx-a11y/aria-proptypes': 'warn',
|
|
'jsx-a11y/role-supports-aria-props': 'warn',
|
|
'jsx-a11y/anchor-has-content': 'warn',
|
|
'jsx-a11y/control-has-associated-label': [
|
|
'warn',
|
|
{ controlComponents: ['Button', 'Switch'] },
|
|
],
|
|
'jsx-a11y/label-has-associated-control': [
|
|
'warn',
|
|
{ labelComponents: ['Label'], controlComponents: ['Input', 'Switch'] },
|
|
],
|
|
'jsx-a11y/aria-role': 'warn',
|
|
'jsx-a11y/no-redundant-roles': 'warn',
|
|
'jsx-a11y/no-aria-hidden-on-focusable': 'warn',
|
|
'jsx-a11y/tabindex-no-positive': 'warn',
|
|
'jsx-a11y/anchor-is-valid': 'warn',
|
|
'jsx-a11y/heading-has-content': 'warn',
|
|
'jsx-a11y/no-distracting-elements': 'warn',
|
|
'valtio/state-snapshot-rule': 'warn',
|
|
'valtio/avoid-this-in-proxy': 'error',
|
|
'react-hook-form/destructuring-formstate': 'error',
|
|
'react-hook-form/no-access-control': 'error',
|
|
'react-hook-form/no-nested-object-setvalue': 'error',
|
|
'react-hook-form/no-use-watch': 'warn',
|
|
},
|
|
},
|
|
// Analytics SQL wire boundary: every call to a SQL-bearing analytics
|
|
// endpoint (`logs.all` / `logs.all.otel`) must go through
|
|
// `executeAnalyticsSql` so the `SafeLogSqlFragment` brand is enforced at the
|
|
// type level. See .claude/skills/safe-sql-execution/SKILL.md.
|
|
{
|
|
files: ['**/*.ts', '**/*.tsx'],
|
|
ignores: ['data/logs/execute-analytics-sql.ts'],
|
|
rules: {
|
|
'no-restricted-syntax': ['error', ...ANALYTICS_SQL_RESTRICTED_SYNTAX],
|
|
},
|
|
},
|
|
// API route modules are eagerly imported by the TanStack server at boot, so
|
|
// module-scope side effects there are especially dangerous. This block also
|
|
// re-includes the analytics selectors because flat config replaces (not
|
|
// merges) a rule's options for overlapping files.
|
|
{
|
|
files: ['pages/api/**/*.ts', 'pages/api/**/*.tsx', 'routes/**/*.ts', 'routes/**/*.tsx'],
|
|
rules: {
|
|
'no-restricted-syntax': [
|
|
'error',
|
|
...ANALYTICS_SQL_RESTRICTED_SYNTAX,
|
|
NO_MODULE_SCOPE_CREATE_CLIENT,
|
|
],
|
|
},
|
|
},
|
|
])
|