rules:
  - id: auth.go.crypto.bcrypt-low-cost
    languages:
      - go
    severity: WARNING
    message: |
      `bcrypt.GenerateFromPassword` is called with a cost factor below 10. A
      low work factor makes each hash cheap to compute, which lets an attacker
      brute-force stolen password hashes far too quickly. OWASP recommends a
      bcrypt cost of at least 10, and ≥ 12 for new applications, tuned so a
      single hash takes roughly 250ms on your hardware.

      Common LLM-generated mistake: `bcrypt.GenerateFromPassword(pw, 8)`
      because the literal "looks fast enough". Use `bcrypt.DefaultCost` (10)
      or raise the cost factor to 12 or higher.
    # Matches only a numeric literal cost < 10 passed to
    # `bcrypt.GenerateFromPassword`. `metavariable-comparison` constrains $N to
    # numeric literals only, so `bcrypt.DefaultCost`, a cost ≥ 10, or a
    # variable (`bcrypt.GenerateFromPassword(pw, cost)`) are NOT flagged.
    patterns:
      - pattern: bcrypt.GenerateFromPassword($PW, $N)
      - metavariable-comparison:
          metavariable: $N
          comparison: $N < 10
    metadata:
      oauthlint-rule-id: AUTH-GO-CRYPTO-002
      oauthlint-doc-url: https://oauthlint.dev/rules/go-crypto-bcrypt-low-cost
      category: security
      cwe: CWE-916
      owasp: A02:2021
      llm-prevalence: MEDIUM
      technology:
        - bcrypt
      references:
        - https://pkg.go.dev/golang.org/x/crypto/bcrypt#GenerateFromPassword
        - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
        - https://cwe.mitre.org/data/definitions/916.html
