feat(core-eslint): add pii-declaration-must-be-complete rule

Adds the `conformance/pii-declaration-must-be-complete` ESLint rule at
warn severity. The rule detects `custom: { pii: { ... } }` blocks in
Payload config files and warns when any of the four required sub-fields
(`category`, `purpose`, `exportable`, `restrictable`) is missing.

Incomplete PII declarations can produce incorrect audit reports —
sub-second editor feedback catches the gap before it reaches
compliance/data-map.yml.

- Rule + 7 RuleTester fixtures (complete passes, each missing field
  warns, non-pii custom block is no-op, malformed custom.pii is no-op)
- Registered in plugin.js + base.js at "warn"
- Conformance rule count bumped 7 → 8 in CLAUDE.md +
  conformance-quickref.md

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-05-18 18:33:48 +00:00
parent fa1a10c88c
commit 1eb32ab23b
8 changed files with 239 additions and 12 deletions

View File

@@ -52,6 +52,7 @@ export default [
"conformance/component-must-have-story": "warn",
"conformance/component-must-have-test": "warn",
"conformance/atomic-tier-import-direction": "warn",
"conformance/pii-declaration-must-be-complete": "warn",
},
},
{

View File

@@ -8,6 +8,7 @@ import usecaseMustBeWired from "./rules/usecase-must-be-wired.js";
import componentMustHaveStory from "./rules/component-must-have-story.js";
import componentMustHaveTest from "./rules/component-must-have-test.js";
import atomicTierImportDirection from "./rules/atomic-tier-import-direction.js";
import piiDeclarationMustBeComplete from "./rules/pii-declaration-must-be-complete.js";
/**
* The `@repo/core-eslint` conformance plugin. Aggregates custom rules that
@@ -35,6 +36,7 @@ const plugin = {
"component-must-have-story": componentMustHaveStory,
"component-must-have-test": componentMustHaveTest,
"atomic-tier-import-direction": atomicTierImportDirection,
"pii-declaration-must-be-complete": piiDeclarationMustBeComplete,
},
};

View File

@@ -0,0 +1,57 @@
const REQUIRED_FIELDS = ["category", "purpose", "exportable", "restrictable"];
/** @type {import("eslint").Rule.RuleModule} */
export default {
meta: {
type: "problem",
docs: {
description:
"custom.pii blocks in Payload config files must declare all required sub-fields: category, purpose, exportable, restrictable.",
},
schema: [],
messages: {
missingField:
"custom.pii block is missing required field '{{field}}'. Incomplete PII declarations can produce incorrect audit reports.",
},
},
create(context) {
return {
Property(node) {
if (
node.key.type !== "Identifier" ||
node.key.name !== "custom" ||
node.value.type !== "ObjectExpression"
) {
return;
}
const piiProp = node.value.properties.find(
(p) =>
p.type === "Property" &&
p.key.type === "Identifier" &&
p.key.name === "pii",
);
if (!piiProp || piiProp.value.type !== "ObjectExpression") {
return;
}
const presentFields = new Set(
piiProp.value.properties
.filter((p) => p.type === "Property" && p.key.type === "Identifier")
.map((p) => p.key.name),
);
for (const field of REQUIRED_FIELDS) {
if (!presentFields.has(field)) {
context.report({
node: piiProp,
messageId: "missingField",
data: { field },
});
}
}
},
};
},
};

View File

@@ -0,0 +1,163 @@
import { describe, it } from "vitest";
import { RuleTester } from "eslint";
import rule from "./pii-declaration-must-be-complete.js";
const tester = new RuleTester({
languageOptions: {
parser: await import("@typescript-eslint/parser"),
ecmaVersion: "latest",
sourceType: "module",
},
});
describe("pii-declaration-must-be-complete", () => {
it("passes when custom.pii has all required fields", () => {
tester.run("pii-declaration-must-be-complete", rule, {
valid: [
{
code: `
const field = {
slug: "email",
type: "email",
custom: {
pii: {
category: "contact",
purpose: "authentication",
exportable: false,
restrictable: true,
},
},
};
`,
},
],
invalid: [],
});
});
it("fires when category is missing", () => {
tester.run("pii-declaration-must-be-complete", rule, {
valid: [],
invalid: [
{
code: `
const field = {
custom: {
pii: {
purpose: "authentication",
exportable: false,
restrictable: true,
},
},
};
`,
errors: [{ messageId: "missingField", data: { field: "category" } }],
},
],
});
});
it("fires when purpose is missing", () => {
tester.run("pii-declaration-must-be-complete", rule, {
valid: [],
invalid: [
{
code: `
const field = {
custom: {
pii: {
category: "contact",
exportable: false,
restrictable: true,
},
},
};
`,
errors: [{ messageId: "missingField", data: { field: "purpose" } }],
},
],
});
});
it("fires when exportable is missing", () => {
tester.run("pii-declaration-must-be-complete", rule, {
valid: [],
invalid: [
{
code: `
const field = {
custom: {
pii: {
category: "contact",
purpose: "authentication",
restrictable: true,
},
},
};
`,
errors: [
{ messageId: "missingField", data: { field: "exportable" } },
],
},
],
});
});
it("fires when restrictable is missing", () => {
tester.run("pii-declaration-must-be-complete", rule, {
valid: [],
invalid: [
{
code: `
const field = {
custom: {
pii: {
category: "contact",
purpose: "authentication",
exportable: false,
},
},
};
`,
errors: [
{ messageId: "missingField", data: { field: "restrictable" } },
],
},
],
});
});
it("is a no-op when custom has no pii property", () => {
tester.run("pii-declaration-must-be-complete", rule, {
valid: [
{
code: `
const field = {
custom: {
someOtherProperty: "value",
},
};
`,
},
],
invalid: [],
});
});
it("is a no-op when custom.pii is not an object", () => {
tester.run("pii-declaration-must-be-complete", rule, {
valid: [
{
code: `
const field = {
custom: {
pii: true,
},
};
`,
},
],
invalid: [],
});
});
});