rules:
  - id: auth.hono.jwt-hardcoded-secret
    languages:
      - javascript
      - typescript
    severity: ERROR
    message: |
      Hono's `jwt()` middleware from `hono/jwt` is configured with a hard-coded
      `secret` string literal. That key signs and verifies every session token:
      committed to git it is one search away from compromise, and anyone who
      reads it can forge a valid token for any user (CWE-798).

      Load the secret from the environment / Workers binding instead and add a
      placeholder to `.env.example`:
        app.use('/auth/*', jwt({ secret: c.env.JWT_SECRET }))
        app.use('/auth/*', jwt({ secret: process.env.JWT_SECRET }))
      Use at least 32 characters for HMAC algorithms, and rotate the leaked
      value out of source control.

      (The `sign()`/`verify()` helpers with a literal secret are covered by
      auth.jwt.weak-secret; this rule targets the Hono middleware config, which
      that rule does not see.)
    # Scoped to the Hono `jwt` middleware imported from `hono/jwt` so a bare
    # `jwt({...})` from another library is not matched. The literal requirement
    # (quoted value) excludes `c.env.*` / `process.env.*` reads; the allow-list
    # drops `${ENV}` templates, `<placeholders>`, and obvious stubs so doc/dev
    # scaffolding does not false-positive.
    patterns:
      - pattern-inside: |
          import { ..., jwt, ... } from 'hono/jwt'
          ...
      - pattern: 'jwt({ ..., secret: $S, ... })'
      - metavariable-pattern:
          metavariable: $S
          patterns:
            - pattern-regex: ^['"].*['"]$
            - pattern-not-regex: (?i)^['"]\$\{?[A-Za-z_]+\}?['"]$
            - pattern-not-regex: (?i)^['"]<[^'"]*>['"]$
            - pattern-not-regex: (?i)^['"](?:your[-_]|my[-_]|example|placeholder|xxx+|todo|fixme|test|dummy|fake|sample|changeme|change[-_]?me|redacted|replace)
    metadata:
      oauthlint-rule-id: AUTH-HONO-001
      oauthlint-doc-url: https://oauthlint.dev/rules/hono-jwt-hardcoded-secret
      category: security
      cwe: CWE-798
      owasp: API2:2023
      llm-prevalence: HIGH
      technology:
        - hono
      references:
        - https://hono.dev/docs/middleware/builtin/jwt
        - https://hono.dev/docs/helpers/jwt
        - https://cwe.mitre.org/data/definitions/798.html
