rules:
  - id: auth.go.tls.insecure-skip-verify
    languages:
      - go
    severity: ERROR
    message: |
      A `tls.Config` sets `InsecureSkipVerify: true`, disabling TLS certificate verification.
      This turns off verification of the server's certificate chain and host
      name, so any attacker who can intercept the connection can present any
      certificate and read or tamper with the traffic: a classic
      man-in-the-middle hole. For OAuth/OIDC this leaks authorization codes,
      access tokens, and client secrets in transit.

      Never set `InsecureSkipVerify: true`. Leave verification on (the default).
      To trust a private CA in development, set `RootCAs` to a `*x509.CertPool`
      loaded with that CA instead.
    # Matches only the literal `true`. `InsecureSkipVerify: false` and the
    # field's absence are not flagged. The `pattern-inside` keeps detection
    # scoped to a `tls.Config{...}` (and `&tls.Config{...}`) composite literal,
    # so an unrelated struct that happens to expose an `InsecureSkipVerify`
    # field is never matched. Narrowing the matched node to the field itself
    # (rather than the whole literal) is what lets the autofix below rewrite
    # just that field and leave the surrounding `...` fields untouched.
    patterns:
      - pattern-inside: 'tls.Config{...}'
      - pattern: 'InsecureSkipVerify: true'
    # Safe, deterministic autofix: flip the boolean to `false`, the secure
    # default that restores certificate verification and fully resolves the
    # finding. Only the `true` literal changes; every other field in the
    # `tls.Config` is preserved verbatim.
    fix: 'InsecureSkipVerify: false'
    metadata:
      oauthlint-rule-id: AUTH-GO-TLS-001
      oauthlint-doc-url: https://oauthlint.dev/rules/go-tls-insecure-skip-verify
      category: security
      cwe: CWE-295
      owasp: A02:2021
      llm-prevalence: HIGH
      technology:
        - crypto/tls
      references:
        - https://pkg.go.dev/crypto/tls#Config
        - https://cwe.mitre.org/data/definitions/295.html
