rules:
  - id: auth.express.cookie-parser-secret
    languages:
      - javascript
      - typescript
    severity: ERROR
    message: |
      `cookie-parser` is initialised with a hard-coded string secret
      (`cookieParser('some-secret')`). That secret signs every signed cookie
      (`res.cookie(name, val, { signed: true })`, read back from
      `req.signedCookies`). Anyone who reads it from your source or git history
      can forge signed cookies and tamper with values your app trusts.

      Load the secret from the environment (`cookieParser(process.env.COOKIE_SECRET)`)
      or a secret manager, and rotate the leaked value out of source control.
      Add a placeholder to `.env.example` so contributors know it is required.
    # The metavariable-pattern requires $S to be a quoted string literal, so
    # `process.env.COOKIE_SECRET`, `config.cookieSecret`, and the no-argument
    # form `cookieParser()` (unsigned cookies) never match.
    patterns:
      - pattern-either:
          - pattern: cookieParser($S)
          - pattern: cookieParser($S, $OPTS)
      - metavariable-pattern:
          metavariable: $S
          patterns:
            - pattern-regex: ^['"].*['"]$
    metadata:
      oauthlint-rule-id: AUTH-EXPRESS-004
      oauthlint-doc-url: https://oauthlint.dev/rules/express-cookie-parser-secret
      category: security
      cwe: CWE-798
      owasp: A07:2021
      llm-prevalence: MEDIUM
      technology:
        - express
        - cookie-parser
      references:
        - https://github.com/expressjs/cookie-parser#cookieparsersecret-options
        - https://cwe.mitre.org/data/definitions/798.html
