rules:
  - id: auth.rust.oauth.ropc-grant
    languages:
      - rust
    severity: ERROR
    message: |
      OAuth token request uses the Resource Owner Password Credentials
      grant (`grant_type=password`). The app collects the user's password
      and replays it to the authorization server, exactly what OAuth was
      designed to avoid. It cannot support federation, MFA, or step-up
      auth, and any compromise of your service exposes raw user passwords.

      The OAuth 2.0 Security BCP (RFC 9700 §2.4) forbids ROPC and OAuth 2.1
      removes it entirely. Use the authorization-code flow with PKCE
      (`grant_type=authorization_code`) for user login, or
      `client_credentials` for machine-to-machine. With the `oauth2` crate,
      use `authorize_url` / `exchange_code` instead of `exchange_password`.
    pattern-either:
      # oauth2 crate ROPC helper: its only purpose is the password grant.
      - pattern: $C.exchange_password(...)
      # reqwest / hand-built form pair: ("grant_type", "password"). The value
      # is bounded so `password_reset` and friends are not matched.
      - pattern-regex: |-
              "grant_type"\s*,\s*"password"
      # URL-encoded request body string: "grant_type=password&username=…".
      - pattern-regex: |-
              [?&"]grant_type=password(?:[&"\s\\]|$)
    # We flag an application sending ROPC, not the example/test code or vendored
    # client libraries that legitimately exercise the grant. Excluding these
    # trees keeps the signal on first-party application code. (`tests.rs` is the
    # Rust convention for a sibling test module file, e.g. oauth2-rs'
    # `src/token/tests.rs`.)
    paths:
      exclude:
        - "**/test/**"
        - "**/tests.rs"
        - "**/*_test.*"
        - "**/*.test.*"
        - "**/example/**"
        - "**/examples/**"
        - "**/mock*/**"
        - "**/vendor/**"
        - "**/node_modules/**"
        - "**/target/**"
    metadata:
      oauthlint-rule-id: AUTH-RUST-OAUTH-001
      oauthlint-doc-url: https://oauthlint.dev/rules/rust-oauth-ropc-grant
      category: security
      cwe: CWE-522
      owasp: API2:2023
      llm-prevalence: MEDIUM
      technology:
        - oauth2
      references:
        - https://datatracker.ietf.org/doc/html/rfc9700#section-2.4
        - https://datatracker.ietf.org/doc/html/draft-ietf-oauth-v2-1#section-2.4
        - https://cwe.mitre.org/data/definitions/522.html
