New
Introducing React Bench, see how different models perform on React code

react-doctor/no-prevent-default

Use `<form action={serverAction}>` (works without JS) or `<button>` instead of `<a>` with preventDefault

Status
Active
Category
Correctness
Assessment
Evidence-required risk
Required evidence
source code
Default configuration
Enabled
Default severity
warn
Show technical metadata
Scope
All supported frameworks
Active when
always
Tags
test-noise
Priority
50 (P2)
Source
oxlint-plugin-react-doctor
Rule set
oxlint-plugin-react-doctor 0.9.3 (prompt schema 2)
On this page

Validation prompt

Confirm the detector match and collect the required evidence before deciding whether an edit is warranted.

Rule fires on <form onSubmit={handler}> or <a onClick={handler}> whose inline handler contains any .preventDefault() call. For anchors, confirm the element is being misused as an action or router interception. For forms, preventDefault is normal in client-only flows, local validation, uploads, offline handling, and SPA submission; syntax alone does not prove a Server Action is appropriate.

Evidence boundary

The diagnostic proves only that the detector’s modeled source pattern matched. It does not prove runtime impact, product intent, rendered failure, or that one remediation is correct.

Establish the environment, repository policy, exceptions, and required rendered or runtime evidence before deciding the occurrence.

Record one outcome:

  • Confirmed failure: The required evidence establishes the violation.
  • Rejected: A documented exception or false-positive predicate applies.
  • Needs evidence: Named evidence can still be collected.
  • Unavailable: Required evidence cannot be collected in this run.
  • Waived with evidence: An authorized, scoped exception applies to an established failure.
  • Observation: The review records an optional tradeoff without claiming a defect.

A waiver records its scope, authority, evidence, and review condition. It is not a pass or false positive.

Default severity is registry metadata. Use the occurrence’s JSON severity after repository configuration when ordering real findings.

Fix prompt

Apply this candidate correction only after the required evidence confirms the risk.

For anchors, use a button for an action or the router's Link for navigation instead of an href='#' interception. For forms, keep onSubmit plus preventDefault when the product intentionally owns a client-side submission lifecycle. Use <form action={serverAction}> only for a server mutation in a React/framework environment that supports Actions and after preserving validation, pending, error, and progressive-enhancement behavior. See https://react.dev/reference/react-dom/components/form

Repository-wide copy prompt

Use this repository-wide prompt only after validating each occurrence. For one occurrence, use the guidance above.

Show repository-wide prompt

Fix every confirmed react-doctor/no-prevent-default diagnostic in the current repository.

Required change:

  • For anchors, use a button for an action or the router's Link for navigation instead of an href='#' interception. For forms, keep onSubmit plus preventDefault when the product intentionally owns a client-side submission lifecycle. Use <form action={serverAction}> only for a server mutation in a React/framework environment that supports Actions and after preserving validation, pending, error, and progressive-enhancement behavior. See https://react.dev/reference/react-dom/components/form.

Validation before editing:

Rule fires on <form onSubmit={handler}> or <a onClick={handler}> whose inline handler contains any .preventDefault() call. For anchors, confirm the element is being misused as an action or router interception. For forms, preventDefault is normal in client-only flows, local validation, uploads, offline handling, and SPA submission; syntax alone does not prove a Server Action is appropriate.

Constraints:

  • Make the smallest change that fixes the root cause.
  • Preserve behavior and interfaces unrelated to this diagnostic.
  • Reuse existing project components, utilities, and conventions.
  • Adapt identifiers and framework details instead of copying blindly.
  • Do not disable the rule or suppress matching code.

Assessment:

  • Record detector evidence, applicability facts, assumptions, missing evidence, and the rule class for this occurrence.
  • Return one outcome: Confirmed failure, Rejected, Needs evidence, Unavailable, Waived with evidence, or Observation.
  • A waiver records the established failure, scope, authority, evidence, and review or expiry condition. It is not a pass or false positive.

Verification:

  • Run focused tests for the changed behavior.
  • Run React Doctor and confirm this diagnostic no longer appears from changed code.
  • Run an unfiltered scan of the affected scope before claiming no cross-category regression.
  • Report the files changed and any checks you could not run.