rules:
  - id: auth.kotlin.android.hardcoded-secret
    languages:
      - kotlin
    severity: ERROR
    message: |
      An OAuth client secret / API key / password is assigned from a hard-coded
      string literal. A secret shipped inside an APK is trivially recovered by
      decompiling the app, so a "confidential" client secret embedded in a mobile
      binary is effectively public (CWE-798). AI-generated Android samples inline
      the value to make the snippet compile and it ships in the release build.

      A public mobile client should use PKCE and hold no client secret at all;
      any unavoidable key belongs in the build config or a secret store, not in
      source:
        val clientSecret = BuildConfig.CLIENT_SECRET   // injected at build time
        val apiKey = System.getenv("API_KEY")
      and rotate any secret already committed.
    # Fires only when the NAME denotes a credential AND the value is a literal
    # string of secret-like length/charset. BuildConfig.* and System.getenv(...)
    # are not string literals, so they are structurally excluded; a placeholder
    # allow-list drops doc stubs.
    patterns:
      - pattern-either:
          - pattern: val $NAME = $VAL
          - pattern: var $NAME = $VAL
          - pattern: const val $NAME = $VAL
      - metavariable-regex:
          metavariable: $NAME
          regex: '(?i).*(client_secret|clientsecret|api[_-]?key|secret|password|bearer|access_token|private_key).*'
      - metavariable-regex:
          metavariable: $VAL
          regex: '^"[A-Za-z0-9_\-+/=]{16,}"$'
      - pattern-not-regex: '(?i)=\s*"(?:your[-_]|example|placeholder|xxx+|todo|changeme|change[-_]?me|replace|dummy|sample|test[-_])'
    metadata:
      oauthlint-rule-id: AUTH-KOTLIN-ANDROID-002
      oauthlint-doc-url: https://oauthlint.dev/rules/kotlin-android-hardcoded-secret
      category: security
      cwe: CWE-798
      owasp: API2:2023
      llm-prevalence: HIGH
      technology:
        - android
      references:
        - https://developer.android.com/privacy-and-security/security-tips#UserData
        - https://cwe.mitre.org/data/definitions/798.html
