rules:
  - id: auth.nestjs.cors-wildcard-credentials
    languages:
      - javascript
      - typescript
    severity: ERROR
    message: |
      NestJS `app.enableCors()` is configured with a wildcard/reflected origin
      (`origin: '*'` or `origin: true`) together with `credentials: true`. The
      CORS spec forbids `Access-Control-Allow-Origin: *` with credentials, so
      `origin: true` echoes the caller's origin back instead, effectively
      allowing credentialed cross-site requests from ANYWHERE. That is a
      CSRF / account-takeover primitive.

      Enumerate the exact trusted origins instead:
      `app.enableCors({ origin: ['https://app.example.com'], credentials: true })`.
      If the API is public and needs no cookies or auth headers, keep
      `credentials` at its default `false`.
    # Requires BOTH the wildcard/reflected origin AND credentials: true on the
    # same enableCors() call (either key order). A scoped origin (a string URL,
    # an array allowlist, or a validating function) with credentials is the
    # recommended shape and never matches; a wildcard origin without credentials
    # is a public API and is left alone.
    pattern-either:
      - pattern: '$APP.enableCors({ ..., origin: "*", ..., credentials: true, ... })'
      - pattern: '$APP.enableCors({ ..., credentials: true, ..., origin: "*", ... })'
      - pattern: '$APP.enableCors({ ..., origin: true, ..., credentials: true, ... })'
      - pattern: '$APP.enableCors({ ..., credentials: true, ..., origin: true, ... })'
    paths:
      exclude:
        - "**/test/**"
        - "**/__tests__/**"
        - "**/*.test.*"
        - "**/*.spec.*"
        - "**/example/**"
        - "**/examples/**"
        - "**/demo/**"
        - "**/benchmark/**"
        - "**/benchmarks/**"
        - "**/integration/**"
        - "**/*.tst.*"
    metadata:
      oauthlint-rule-id: AUTH-NESTJS-003
      oauthlint-doc-url: https://oauthlint.dev/rules/nestjs-cors-wildcard-credentials
      category: security
      cwe: CWE-942
      owasp: API8:2023
      llm-prevalence: MEDIUM
      technology:
        - nestjs
      references:
        - https://docs.nestjs.com/security/cors
        - https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS/Errors/CORSNotSupportingCredentials
