rules:
  - id: auth.kotlin.secret.hardcoded-jwt-secret
    languages:
      - kotlin
    severity: ERROR
    message: |
      A JWT signing key is built from a hard-coded string literal
      (`Algorithm.HMAC256("...")`). This key both signs and verifies every token:
      committed to source control it is one search away from compromise, letting
      an attacker forge tokens for any user or role (CWE-798). This is a common
      AI-generated mistake: a literal secret is inlined to make the Ktor/java-jwt
      sample "just work" and is never externalized.

      Load the key from configuration or a secret store instead, e.g.
      `Algorithm.HMAC256(System.getenv("JWT_SECRET"))` or
      `Algorithm.HMAC256(environment.config.property("jwt.secret").getString())`,
      and rotate any secret that has already been checked in.
    # Auth0 java-jwt (com.auth0.jwt): flag ONLY a string literal in the HMAC key
    # position. A variable, System.getenv(...), or a config read is not a `"..."`
    # literal and is structurally excluded. A regex allow-list drops obvious
    # placeholders / doc stubs and `${ENV}` templates.
    patterns:
      - pattern-either:
          - pattern: com.auth0.jwt.algorithms.Algorithm.HMAC256("...")
          - pattern: com.auth0.jwt.algorithms.Algorithm.HMAC384("...")
          - pattern: com.auth0.jwt.algorithms.Algorithm.HMAC512("...")
          - pattern: Algorithm.HMAC256("...")
          - pattern: Algorithm.HMAC384("...")
          - pattern: Algorithm.HMAC512("...")
      - pattern-not-regex: '(?i)HMAC(?:256|384|512)\(\s*"\\?\$\{?[A-Za-z_]+\}?"'
      - pattern-not-regex: '(?i)HMAC(?:256|384|512)\(\s*"<[^"]*>"'
      - pattern-not-regex: '(?i)HMAC(?:256|384|512)\(\s*"(?:your[-_]|example|placeholder|xxx+|todo|changeme|change[-_]?me|replace)'
    metadata:
      oauthlint-rule-id: AUTH-KOTLIN-SECRET-001
      oauthlint-doc-url: https://oauthlint.dev/rules/kotlin-secret-hardcoded-jwt-secret
      category: security
      cwe: CWE-798
      owasp: API2:2023
      llm-prevalence: HIGH
      technology:
        - java-jwt
        - ktor
      references:
        - https://github.com/auth0/java-jwt
        - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
        - https://cwe.mitre.org/data/definitions/798.html
