rules:
  - id: auth.go.session.hardcoded-secret
    languages:
      - go
    severity: ERROR
    message: |
      A gorilla/sessions or securecookie store is initialized with a hardcoded
      string-literal key. This key authenticates (and, for securecookie,
      encrypts) every session cookie: anyone who reads the source or git
      history can forge a valid session for any user, a complete
      authentication bypass (CWE-798). This is a common AI-generated shortcut:
      a literal key is inlined so the sample "just works" and is never
      externalized.

      Load the key(s) from configuration or a secret manager and generate them
      with a CSPRNG, e.g.
        store := sessions.NewCookieStore([]byte(os.Getenv("SESSION_KEY")))
      Rotate any key that has already been committed to source control.
    # Only a `[]byte("literal")` in key position fires. The `"..."`
    # metavariadic matches a string-literal AST node only, so
    # `[]byte(os.Getenv("SESSION_KEY"))` and `[]byte(secretVar)` are NOT
    # matched. Covers gorilla/sessions `NewCookieStore` / `NewFilesystemStore`
    # (variadic keyPairs) and gorilla/securecookie `New(hashKey, blockKey)`.
    # A regex allow-list drops obvious placeholders / `${ENV}` templates.
    patterns:
      - pattern-either:
          - pattern: sessions.NewCookieStore(..., []byte("..."), ...)
          - pattern: sessions.NewFilesystemStore($P, ..., []byte("..."), ...)
          - pattern: securecookie.New([]byte("..."), ...)
      - pattern-not-regex: |-
          (?i)\[\]byte\(\s*["']\$\{?[A-Za-z_]+\}?["']
      - pattern-not-regex: |-
          (?i)\[\]byte\(\s*["'](?:your[-_]|example|placeholder|xxx+|todo|changeme|change[-_]?me|replace|secret-key|<)
    paths:
      exclude:
        - "**/test/**"
        - "**/*_test.go"
        - "**/example/**"
        - "**/examples/**"
        - "**/vendor/**"
    metadata:
      oauthlint-rule-id: AUTH-GO-SESSION-001
      oauthlint-doc-url: https://oauthlint.dev/rules/go-session-hardcoded-secret
      category: security
      cwe: CWE-798
      owasp: API2:2023
      llm-prevalence: HIGH
      technology:
        - gorilla-sessions
        - gorilla-securecookie
      references:
        - https://github.com/gorilla/sessions
        - https://github.com/gorilla/securecookie
        - https://cwe.mitre.org/data/definitions/798.html
