rules:
  - id: auth.hono.cors-reflect-credentials
    languages:
      - javascript
      - typescript
    severity: ERROR
    message: |
      Hono's `cors()` middleware is given an `origin` function that reflects the
      caller's origin straight back (`origin: (origin) => origin`) together with
      `credentials: true`. This echoes ANY requesting origin into
      `Access-Control-Allow-Origin` while allowing cookies and `Authorization`
      headers, effectively "allow credentialed cross-site requests from
      anywhere", a CSRF / account-takeover primitive (CWE-942).

      Validate the origin against an allow-list before returning it, or pass an
      explicit list:
        cors({ origin: ['https://app.example.com'], credentials: true })
        cors({ origin: (o) => (allowed.includes(o) ? o : null), credentials: true })
      If the API is public and needs no cookies/auth headers, drop
      `credentials` (defaults to false).

      (A literal `origin: '*'` with credentials is covered by
      auth.cors.wildcard-with-credentials; this rule targets the Hono
      reflect-the-origin function form, which that rule does not match.)
    # Fires ONLY when the origin callback returns its own argument unchanged
    # (a naive reflect) AND credentials is enabled, either key order, with or
    # without the second `context` parameter Hono passes. A callback that runs
    # any validation (`allowed.includes(o) ? o : null`) has a different body and
    # is not matched, and a reflect callback WITHOUT credentials (a public API)
    # is left alone.
    patterns:
      - pattern-either:
          - pattern: 'cors({ ..., origin: ($O) => $O, ..., credentials: true, ... })'
          - pattern: 'cors({ ..., credentials: true, ..., origin: ($O) => $O, ... })'
          - pattern: 'cors({ ..., origin: ($O, $C) => $O, ..., credentials: true, ... })'
          - pattern: 'cors({ ..., credentials: true, ..., origin: ($O, $C) => $O, ... })'
    metadata:
      oauthlint-rule-id: AUTH-HONO-002
      oauthlint-doc-url: https://oauthlint.dev/rules/hono-cors-reflect-credentials
      category: security
      cwe: CWE-942
      owasp: API8:2023
      llm-prevalence: MEDIUM
      technology:
        - hono
      references:
        - https://hono.dev/docs/middleware/builtin/cors
        - https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS/Errors/CORSNotSupportingCredentials
        - https://cwe.mitre.org/data/definitions/942.html
