rules:
  - id: auth.csharp.cors.reflect-any-origin-credentials
    languages:
      - csharp
    severity: ERROR
    message: |
      A CORS policy combines credentialed requests with a wildcard or reflected
      origin (`AllowCredentials()` together with `AllowAnyOrigin()` or
      `SetIsOriginAllowed(...)` that returns true for everything). This lets any
      website make cross-origin requests carrying the user's cookies and read the
      response, which is a cross-site data-theft and CSRF primitive (CWE-942).
      This is a common AI-generated mistake made to "just make CORS work".

      Never pair `AllowCredentials()` with a wildcard/reflected origin. Pin an
      explicit allow-list with `WithOrigins("https://app.example.com")` and only
      then call `AllowCredentials()`.
    # Anchored to a policy builder that chains origin reflection/wildcard with
    # AllowCredentials, in either order. A plain reflected origin without
    # credentials, or an explicit WithOrigins allow-list, does not fire.
    patterns:
      - pattern-either:
          - pattern: $B.SetIsOriginAllowed(...).AllowCredentials()
          - pattern: $B.AllowCredentials().SetIsOriginAllowed(...)
          - pattern: $B.AllowAnyOrigin().AllowCredentials()
          - pattern: $B.AllowCredentials().AllowAnyOrigin()
    paths:
      exclude:
        - "**/test/**"
        - "**/*.Tests/**"
        - "**/*.Test/**"
        - "**/samples/**"
        - "**/sandbox/**"
        - "**/example/**"
        - "**/examples/**"
        - "**/demo/**"
        - "**/benchmark/**"
    metadata:
      oauthlint-rule-id: AUTH-CSHARP-CORS-001
      oauthlint-doc-url: https://oauthlint.dev/rules/csharp-cors-reflect-any-origin-credentials
      category: security
      cwe: CWE-942
      owasp: API8:2023
      llm-prevalence: HIGH
      technology:
        - aspnetcore
        - cors
      references:
        - https://learn.microsoft.com/aspnet/core/security/cors
        - https://cwe.mitre.org/data/definitions/942.html
