# @movable/eslint-plugin-no-wildcard-postmessage

> custom ESLint rule to disallows calling postMessage to wildcard targets

Latest version **1.0.0** (published 2020-04-21) · MPL-2.0 license · 0 weekly downloads

## Install

```sh
npm install @movable/eslint-plugin-no-wildcard-postmessage
pnpm add @movable/eslint-plugin-no-wildcard-postmessage
yarn add @movable/eslint-plugin-no-wildcard-postmessage
bun add @movable/eslint-plugin-no-wildcard-postmessage
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.0 |
| Published | 2020-04-21 |
| First published | 2020-04-21 |
| Weekly downloads | 0 |
| License | MPL-2.0 |
| TypeScript types | none |
| Module format | CommonJS |
| Node | >= 10 |
| Dependencies | 0 |
| Unpacked size | 25.5 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 5 |
| Author | Frederik Braun |
| Maintainers | megoetzke, cwervo, alexlafroscia, pcarbajal, mansurtsutiev, nicksteffens_mi, kruggeri, psalant726, joxamo18, uyethon, mnutt, shyshy, spencer516 |
| Keywords | eslint, eslint-plugin, eslintplugin, lint, security |

## Links

- npm: https://www.npmjs.com/package/@movable/eslint-plugin-no-wildcard-postmessage
- Repository: https://github.com/mozfreddyb/eslint-plugin-no-wildcard-postmessage/issues
- Homepage: https://github.com/mozfreddyb/eslint-plugin-no-wildcard-postmessage/
- Issues: https://github.com/mozfreddyb/eslint-plugin-no-wildcard-postmessage/issues
- npm.io page: https://npm.io/package/@movable/eslint-plugin-no-wildcard-postmessage

## Alternatives

- [eslint-plugin-sonarjs](https://npm.io/package/eslint-plugin-sonarjs.md) — 2.9M weekly downloads
- [eslint-config-expo](https://npm.io/package/eslint-config-expo.md) — 1.5M weekly downloads
- [@matter/protocol](https://npm.io/package/@matter/protocol.md) — 63.5K weekly downloads
- [@eventcatalog/linter](https://npm.io/package/@eventcatalog/linter.md) — 24.8K weekly downloads
- [@pandacss/eslint-plugin](https://npm.io/package/@pandacss/eslint-plugin.md) — 18.7K weekly downloads

## Recent versions

- 1.0.0 (latest) — 2020-04-21

## README

[![Build Status](https://travis-ci.org/mozfreddyb/eslint-plugin-no-wildcard-postmessage.svg?branch=master)](https://travis-ci.org/mozfreddyb/eslint-plugin-no-wildcard-postmessage)

# Disallow wildcard targets for postMessage (no-wildcard-postmessage)

This function disallows unsafe coding practices that may result into security vulnerabilities.
We will postMessage calls that contain a target origin of `"*"`.

## Rule Details

Disallowed:

```js
frame.postMessage(obj, "*");

```

A few examples of allowed practices:


```js
frame.postMessage(obj, "http://domain.tld");
// in a worker:
postMessage(obj);
```


This rule is being used within Mozilla to maintain and improve the security of the Firefox OS front-end codebase *Gaia*. Further documentation, which includes references to the escaping functions can be found on [MDN](https://developer.mozilla.org/en-US/Firefox_OS/Security/Security_Automation).

---
_Source: https://npm.io/package/@movable/eslint-plugin-no-wildcard-postmessage · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
