kibana/packages/kbn-eslint-plugin-eslint/README.mdx
Jeramy Soucy 2627f48d95
Harden console functions (#171367)
## Summary

This PR overrides console functions only in production, in order to
sanitize input parameters for any potential calls made to the global
console from Kibana's dependencies.

This initial implementation overrides the `debug`, `error`, `info`,
`log`, `trace`, and `warn` functions, and only sanitizes string inputs.
Future updates may expand this to handle other types, or strings nested
in objects.

The unmodified console methods are now exposed internally in Kibana as
`unsafeConsole`. Where needed for formatting (log appenders, core
logger), calls to the global console have been replaced by
`unsafeConsole`. This PR also adds a new es linting rule to disallow
calls to `unsafeConsole` unless `eslint-disable-next-line
@kbn/eslint/no_unsafe_console` is used.

### Testing
Not sure how we could test this. The overrides are only enabled when
running in a true production environment (e.g. docker) by checking
`process.env.NODE_ENV`.

I was able to manually test by adding additional console output denoting
when the console functions were being overriden or not.

Closes https://github.com/elastic/kibana-team/issues/664
Closes #176340

---------

Co-authored-by: kibanamachine <42973632+kibanamachine@users.noreply.github.com>
2024-02-09 09:13:52 -05:00

110 lines
No EOL
2.5 KiB
Text

---
id: kibDevDocsOpsEslintPluginEslint
slug: /kibana-dev-docs/ops/eslint-plugin-eslint
title: "@kbn/eslint-plugin-eslint"
description: A package holding an eslint plugin with custom rules used on Kibana
date: 2022-05-17
tags: ['kibana', 'dev', 'contributor', 'operations', 'eslint', 'plugin']
---
An ESLint plugin exposing custom rules used and built specifically for development within Kibana.
Next you can find information on each on.
## disallow-license-headers
Disallows a given group of license header texts on a group of files.
```javascript
module.exports = {
overrides: [
{
files: ['**/*.{js,mjs,ts,tsx}'],
rules: {
'@kbn/eslint/disallow-license-headers': [
'error',
{
licenses: [
"LICENSE_TEXT"
],
},
],
}
}
]
}
```
## module_migration
Offers a way to force a migration from a given node module into another as an alternative.
```javascript
module.exports = {
overrides: [
{
files: ['**/*.{js,mjs,ts,tsx}'],
rules: {
'@kbn/eslint/module_migration': [
'error',
[
{
from: 'expect.js',
to: '@kbn/expect',
}
],
],
}
}
]
}
```
## no_async_foreach
Disallows passing an async function to .forEach which will avoid promise rejections from being handled. asyncForEach() or a similar helper from "@kbn/std" should be used instead.
## no_async_promise_body
Disallows the usage of an async function as a constructor for a Promise function without a try catch in place.
## no_constructor_args_in_property_initializers
Disallows the usage of constructor arguments into class property initializers.
## no_export_all
Disables the usage of `export *`.
## no_this_in_property_initializers
Disallows the usage of `this` into class property initializers and enforce to define the property value into the constructor.
## no_trailing_import_slash
Disables the usage of a trailing slash in a node module import.
## require-license-header
Requires a given license header text on a group of files.
```javascript
module.exports = {
overrides: [
{
files: ['**/*.{js,mjs,ts,tsx}'],
rules: {
'@kbn/eslint/require-license-header': [
'error',
{
license: "LICENSE_TEXT"
},
],
}
}
]
}
```
## no_unsafe_console
Disables the usage of kbn-security-hardening/console/unsafeConsole.