rules:
  - id: auth.java.cors.credentialed-wildcard
    languages:
      - java
    severity: ERROR
    message: |
      CORS is configured to allow any origin together with credentials. A
      wildcard origin combined with `allowCredentials = true` tells the browser
      to send the victim's cookies and authorization headers to a response that
      any site can read, a cross-origin account-takeover primitive (CWE-942).
      Because browsers reject a literal `*` when credentials are allowed,
      `addAllowedOriginPattern("*")` exists specifically to re-enable this unsafe
      combination, so its very use is the smell.

      Never pair a wildcard origin with credentials. List the exact trusted
      origins (`setAllowedOrigins(List.of("https://app.example.com"))` with
      `setAllowCredentials(true)`) or drop credentials if you genuinely need a
      public, anonymous API.
    # Annotation form: @CrossOrigin with a wildcard origin AND allowCredentials
    # = "true" (both attribute orderings, `origins` and the `value` alias).
    # Programmatic form: the origin-PATTERN wildcard API, which only exists to
    # allow `*` with credentials, flagged on its own. The plain
    # `addAllowedOrigin`/`setAllowedOrigins` wildcards are covered by
    # auth.java.cors.allow-all and are intentionally not duplicated here.
    pattern-either:
      - pattern: '@CrossOrigin(..., origins = "*", ..., allowCredentials = "true", ...)'
      - pattern: '@CrossOrigin(..., allowCredentials = "true", ..., origins = "*", ...)'
      - pattern: '@CrossOrigin(..., value = "*", ..., allowCredentials = "true", ...)'
      - pattern: '@CrossOrigin(..., allowCredentials = "true", ..., value = "*", ...)'
      - pattern: $C.addAllowedOriginPattern("*")
      - pattern: $C.setAllowedOriginPatterns($L(..., "*", ...))
    metadata:
      oauthlint-rule-id: AUTH-JAVA-CORS-002
      oauthlint-doc-url: https://oauthlint.dev/rules/java-cors-credentialed-wildcard
      category: security
      cwe: CWE-942
      owasp: API8:2023
      llm-prevalence: MEDIUM
      technology:
        - spring-web
      references:
        - https://docs.spring.io/spring-framework/reference/web/webmvc-cors.html
        - https://portswigger.net/web-security/cors
        - https://cwe.mitre.org/data/definitions/942.html
