New
Introducing React Bench, see how different models perform on React code

react-doctor/react-router-no-session-mutation-in-loader

Loader mutates session state

  • Category: Bugs
  • Severity: error
  • Source: oxlint-plugin-react-doctor
  • Framework: global
  • Enabled when: react-router:7, react-router-framework
  • Tags: test-noise
  • Default: Enabled

Validate the diagnostic

Confirm the reported code matches this rule before you edit it.

Confirm the reported code matches react-doctor/react-router-no-session-mutation-in-loader. Compare it with the Before example and verify the same API, framework, and execution context. Treat it as a false positive only when one of those conditions differs.

Compare the code

The corrected pattern shows a focused way to address the diagnostic.

Reported pattern

export const loader = async ({ request }) => {
  const session = await getSession(request.headers.get("Cookie"));
  session.set("theme", "dark");
  return redirect("/");
};

Corrected pattern

export const action = async ({ request }) => {
  const session = await getSession(request.headers.get("Cookie"));
  session.set("theme", "dark");
  return redirect("/", {
    headers: { "Set-Cookie": await commitSession(session) },
  });
};

How to fix

Use the corrected pattern as a reference. Preserve behavior that the rule does not require you to change.

Copyable fix prompt

Copy this self-contained prompt into your coding agent after you confirm the diagnostic.

Fix every confirmed react-doctor/react-router-no-session-mutation-in-loader diagnostic in the current repository. Required change: - Mutate and commit sessions in an action, then redirect to a loader.
Reference transformation:Before:
export const loader = async ({ request }) => {
  const session = await getSession(request.headers.get("Cookie"));
  session.set("theme", "dark");
  return redirect("/");
};
After:
export const action = async ({ request }) => {
  const session = await getSession(request.headers.get("Cookie"));
  session.set("theme", "dark");
  return redirect("/", {
    headers: { "Set-Cookie": await commitSession(session) },
  });
};
Constraints: - Confirm the reported code matches the Before pattern. - Make the smallest change that fixes the root cause. - Preserve behavior and interfaces unrelated to this diagnostic. - Reuse existing project components, utilities, and conventions. - Do not introduce render-phase side effects, render-phase state updates, or Hooks rule violations. - Adapt identifiers and framework details instead of copying blindly. - Do not disable the rule or suppress matching code. - Confirm this rule is enabled for the project: react-router:7, react-router-framework. Verification: - Run focused tests for the changed behavior. - Run React Doctor and confirm this diagnostic no longer appears. - Report the files changed and any checks you could not run.

More Bugs rules from the rules reference: