rules:
  - id: auth.go.crypto.weak-password-hash
    languages:
      - go
    severity: ERROR
    message: |
      A password is being hashed with a fast, general-purpose digest from the
      Go standard library (MD5, SHA-1, SHA-256, SHA-512). These algorithms are
      designed to be fast, which makes offline brute-force and rainbow-table
      attacks cheap. They are NOT suitable for storing passwords (CWE-916).

      Use a dedicated, slow password-hashing function with a per-password salt
      and a tunable work factor: bcrypt
      (`golang.org/x/crypto/bcrypt.GenerateFromPassword`), Argon2
      (`golang.org/x/crypto/argon2.IDKey`), or scrypt
      (`golang.org/x/crypto/scrypt.Key`). These resist brute-force by design.
    # Anchored to the *password* character of the input: the digested/written
    # argument must be named like a password (metavariable-regex on $PW). This
    # avoids flagging `sha256.Sum256(fileBytes)` for file checksums or
    # non-password fingerprints, and does not touch real password hashers
    # (bcrypt/argon2/scrypt). Both the one-shot `Sum`/`Sum256`/`Sum512` form
    # and the streaming `h := md5.New(); h.Write([]byte(password))` writer form
    # are covered.
    patterns:
      - pattern-either:
          - pattern: md5.Sum([]byte($PW))
          - pattern: sha1.Sum([]byte($PW))
          - pattern: sha256.Sum256([]byte($PW))
          - pattern: sha512.Sum512([]byte($PW))
          - pattern: $H.Write([]byte($PW))
      - metavariable-regex:
          metavariable: $PW
          regex: (?i).*(password|passwd|pwd).*
    metadata:
      oauthlint-rule-id: AUTH-GO-CRYPTO-001
      oauthlint-doc-url: https://oauthlint.dev/rules/go-crypto-weak-password-hash
      category: security
      cwe: CWE-916
      owasp: A02:2021
      llm-prevalence: HIGH
      technology:
        - crypto/md5
        - crypto/sha256
      references:
        - https://cwe.mitre.org/data/definitions/916.html
        - https://pkg.go.dev/golang.org/x/crypto/bcrypt
        - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
