rules:
  - id: auth.kotlin.cors.anyhost-credentials
    languages:
      - kotlin
    severity: ERROR
    message: |
      A Ktor CORS configuration combines `anyHost()` with
      `allowCredentials = true`. This tells the browser to send cookies and
      Authorization headers on cross-origin requests from ANY origin and to expose
      the authenticated response back to that origin, so any malicious website a
      logged-in user visits can call this API with their credentials and read the
      result (CWE-942, Permissive Cross-domain Policy). This is a common
      AI-generated mistake: `anyHost()` is used to "make CORS work" while
      credentials are also enabled.

      Never pair `anyHost()` with credentials. Allow only the specific origins
      that need credentialed access:
        `allowHost("app.example.com", schemes = listOf("https"))`
    # Ktor ktor-server-cors: fire only when the SAME install(CORS) { } block
    # contains both anyHost() and allowCredentials = true. Either one alone is out
    # of scope, so the finding lands exactly on the dangerous combination.
    patterns:
      - pattern-inside: |
          install(CORS) {
            ...
          }
      - pattern-inside: |
          install(CORS) {
            ...
            allowCredentials = true
            ...
          }
      - pattern: anyHost()
    metadata:
      oauthlint-rule-id: AUTH-KOTLIN-CORS-001
      oauthlint-doc-url: https://oauthlint.dev/rules/kotlin-cors-anyhost-credentials
      category: security
      cwe: CWE-942
      owasp: API8:2023
      llm-prevalence: HIGH
      technology:
        - ktor
      references:
        - https://ktor.io/docs/server-cors.html
        - https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#credentialed_requests_and_wildcards
        - https://cwe.mitre.org/data/definitions/942.html
