vue/no-unsafe-url
Warn about potentially unsafe URL bindings
Default severity: warning
Presets: essential, happy-path, nuxt, ecosystem, opinionated
Automatic fix: None; review the suggested change
Applies to: Vue SFC templates and blocks, with script context where the rule requires it
Options: No rule-specific options. Severity and preset selection are configurable.
Configuration (Vite+)
import { defineConfig } from "@vizejs/vite-plugin/vite-plus";
export default defineConfig({
lint: {
vize: {
"preset": "incremental",
"rules": {
"vue/no-unsafe-url": "warn"
}
},
},
});
vp run lint
Bad
The anchor destination begins with the executable javascript: scheme.
<template>
<a href="javascript:alert(1)">Continue</a>
</template>
Good
The anchor uses the ordinary local /next navigation destination.
<template>
<a href="/next">Continue</a>
</template>
Good avoids this rule's finding under the configuration above; other rules may still report diagnostics.