rules:
  - id: auth.go.cookie.insecure
    languages:
      - go
    severity: ERROR
    message: |
      A session/auth `http.Cookie` is created with a security attribute
      explicitly disabled (`Secure: false` or `HttpOnly: false`). With
      `Secure: false` the cookie is sent over plain HTTP, so a network
      attacker can read the session token. With `HttpOnly: false` the cookie
      is readable from JavaScript, so any XSS can steal it. For OAuth/OIDC
      this exposes session and token cookies to theft and hijacking.

      Set `Secure: true` and `HttpOnly: true` on auth cookies, and add an
      appropriate `SameSite` mode (for example `SameSite: http.SameSiteLaxMode`).
    # Matches only the literal `false`. `Secure: true`, `HttpOnly: true`, and
    # the absence of the field are not flagged. The `pattern-inside` keeps
    # detection scoped to an `http.Cookie{...}` (and `&http.Cookie{...}`)
    # composite literal, so an unrelated struct exposing a `Secure`/`HttpOnly`
    # bool is never matched. `$FIELD` captures the offending field name so the
    # narrow match (and the autofix below) targets just that field.
    patterns:
      - pattern-inside: 'http.Cookie{...}'
      - pattern: '$FIELD: false'
      - metavariable-regex:
          metavariable: $FIELD
          regex: ^(Secure|HttpOnly)$
    # Safe, deterministic autofix: flip the disabled flag to `true`. `$FIELD` is
    # preserved, so `Secure: false` becomes `Secure: true` and `HttpOnly: false`
    # becomes `HttpOnly: true`, each the secure value that resolves the finding,
    # with every other field in the literal left untouched.
    fix: '$FIELD: true'
    metadata:
      oauthlint-rule-id: AUTH-GO-COOKIE-001
      oauthlint-doc-url: https://oauthlint.dev/rules/go-cookie-insecure
      category: security
      cwe: CWE-614
      owasp: API8:2023
      llm-prevalence: HIGH
      technology:
        - net/http
      references:
        - https://pkg.go.dev/net/http#Cookie
        - https://cwe.mitre.org/data/definitions/614.html
