react-doctor/no-unsafe-json-parse
Unsafe JSON.parse dereference
- Category: Bugs
- Severity: warn
- Source:
oxlint-plugin-react-doctor - Framework: global
- Enabled when: always
- Tags: test-noise
- Default: Enabled
Validate the diagnostic
Confirm the reported code matches this rule before you edit it.
Confirm the reported code matches react-doctor/no-unsafe-json-parse. Compare it with the Before example and verify the same API, framework, and execution context. Treat it as a false positive only when one of those conditions differs.
Compare the code
The corrected pattern shows a focused way to address the diagnostic.
Reported pattern
const theme = JSON.parse(localStorage.getItem("settings") ?? "{}").theme;Corrected pattern
const readTheme = () => {
const settings = localStorage.getItem("settings") ?? "{}";
try {
const parsedSettings = JSON.parse(settings);
return typeof parsedSettings.theme === "string"
? parsedSettings.theme
: undefined;
} catch {
return undefined;
}
};How to fix
Use the corrected pattern as a reference. Preserve behavior that the rule does not require you to change.
Copyable fix prompt
Copy this self-contained prompt into your coding agent after you confirm the diagnostic.
Fix every confirmed
Reference transformation:Before:react-doctor/no-unsafe-json-parse diagnostic in the current repository.
Required change:
- Wrap JSON.parse(x) in try/catch and validate the result (for example with a schema) before reading properties off it. A bare JSON.parse(x).foo throws on bad input and lets undefined fields slip past the type-checker.const theme = JSON.parse(localStorage.getItem("settings") ?? "{}").theme;const readTheme = () => {
const settings = localStorage.getItem("settings") ?? "{}";
try {
const parsedSettings = JSON.parse(settings);
return typeof parsedSettings.theme === "string"
? parsedSettings.theme
: undefined;
} catch {
return undefined;
}
};Constraints:
- Confirm the reported code matches the Before pattern.
- Make the smallest change that fixes the root cause.
- Preserve behavior and interfaces unrelated to this diagnostic.
- Reuse existing project components, utilities, and conventions.
- Do not introduce render-phase side effects, render-phase state updates, or Hooks rule violations.
- Adapt identifiers and framework details instead of copying blindly.
- Do not disable the rule or suppress matching code.
Verification:
- Run focused tests for the changed behavior.
- Run React Doctor and confirm this diagnostic no longer appears.
- Report the files changed and any checks you could not run.
Related rules
More Bugs rules from the rules reference:
react-doctor/no-whole-object-default-losing-per-key-defaults: Whole-object param default loses per-key defaultsreact-doctor/no-whole-object-dep-with-member-reads: Whole props object in deps while only members are readreact-doctor/no-will-update-set-state: Don't call this.setState in componentWillUpdate — move the update to getDerivedStateFromProps or componentDidUpdate.react-doctor/pointer-capture-needs-cancel-handler: Captured pointer interaction has no cancellation pathreact-doctor/preact-no-children-length: Wrap with toChildArray(children) from preact before reading .length or calling array methods on props.children.