rules:
  - id: auth.rust.oauth.hardcoded-client-secret
    languages:
      - rust
    severity: ERROR
    message: |
      An OAuth `client_secret` is hardcoded as a string literal and passed to
      the `oauth2` crate's `ClientSecret::new(...)`. The client secret
      authenticates your application to the authorization server; committed to
      source control it is one `grep`/git-history search away from compromise,
      letting an attacker impersonate your client, mint tokens, and exchange
      authorization codes (CWE-798). AI-generated snippets inline the secret to
      make the sample "just work" and it ships unchanged.

      Load the secret at runtime from the environment or a secret manager:
        let secret = std::env::var("OAUTH_CLIENT_SECRET")?;
        let client = BasicClient::new(client_id)
            .set_client_secret(ClientSecret::new(secret));
      Never commit client secrets to source control.
    # Only a STRING LITERAL in the `ClientSecret::new(...)` argument is flagged.
    # The four idiomatic literal-to-String conversions below match only when the
    # literal is the direct argument, so `ClientSecret::new(secret)`,
    # `ClientSecret::new(std::env::var("OAUTH_CLIENT_SECRET")?)`, and any other
    # runtime expression are never matched (mirrors auth.rust.oauth.static-state).
    pattern-either:
      - pattern: ClientSecret::new("...".to_string())
      - pattern: ClientSecret::new("...".to_owned())
      - pattern: ClientSecret::new("...".into())
      - pattern: ClientSecret::new(String::from("..."))
      - pattern: oauth2::ClientSecret::new("...".to_string())
      - pattern: oauth2::ClientSecret::new("...".to_owned())
      - pattern: oauth2::ClientSecret::new("...".into())
      - pattern: oauth2::ClientSecret::new(String::from("..."))
    metadata:
      oauthlint-rule-id: AUTH-RUST-OAUTH-005
      oauthlint-doc-url: https://oauthlint.dev/rules/rust-oauth-hardcoded-client-secret
      category: security
      cwe: CWE-798
      owasp: API2:2023
      llm-prevalence: HIGH
      technology:
        - oauth2
      references:
        - https://docs.rs/oauth2/latest/oauth2/struct.ClientSecret.html
        - https://datatracker.ietf.org/doc/html/rfc6749#section-2.3.1
        - https://cwe.mitre.org/data/definitions/798.html
