rules:
  - id: auth.swift.cors.wildcard-with-credentials
    languages:
      - swift
    severity: WARNING
    message: |
      A Vapor `CORSMiddleware.Configuration` combines `allowedOrigin: .all` (the
      `*` wildcard) with `allowCredentials: true`. This tells browsers to send
      cookies and Authorization headers to a resource that accepts every origin,
      which lets any site read authenticated responses on the user's behalf, the
      classic wildcard-plus-credentials CORS misconfiguration (CWE-942). The
      browser will actually refuse `*` with credentials, so AI-generated fixes
      that "reflect the origin" recreate the same hole against every caller.

      Restrict the origin to a known allow-list, e.g.
      `allowedOrigin: .custom("https://app.example.com")` (or `.any([...])`), or
      set `allowCredentials: false` if no cookies/credentials are needed.
    patterns:
      - pattern: CORSMiddleware.Configuration(...)
      - pattern: 'CORSMiddleware.Configuration(..., allowedOrigin: .all, ...)'
      - pattern: 'CORSMiddleware.Configuration(..., allowCredentials: true, ...)'
    paths:
      exclude:
        - "**/test/**"
        - "**/Tests/**"
        - "**/*Tests.swift"
        - "**/*Test.swift"
        - "**/example/**"
        - "**/examples/**"
    metadata:
      oauthlint-rule-id: AUTH-SWIFT-CORS-001
      oauthlint-doc-url: https://oauthlint.dev/rules/swift-cors-wildcard-with-credentials
      category: security
      cwe: CWE-942
      owasp: API8:2023
      llm-prevalence: MEDIUM
      technology:
        - vapor
      references:
        - https://docs.vapor.codes/advanced/middleware/
        - https://cwe.mitre.org/data/definitions/942.html
