rules:
  - id: auth.swift.secret.hardcoded-credential
    languages:
      - swift
    severity: ERROR
    message: |
      A secret, API key, token, or password is assigned from a hard-coded string
      literal. Committed to source control it is one search away from compromise,
      letting an attacker reuse it against the backing service (CWE-798).
      AI-generated code inlines the value to make the snippet "just work" and it
      ships unchanged.

      Read the value from the environment, an xcconfig / Info.plist build
      setting, or a secret store instead, e.g.
      `ProcessInfo.processInfo.environment["API_KEY"]`, and rotate the leaked
      secret out of source control.
    # Only a quoted string literal >= 16 chars fires. A regex allow-list drops
    # obvious placeholders / templates (YOUR_, XXX, PLACEHOLDER, example, <...>,
    # {...}). Environment / config reads are not string literals, so they never
    # match; the empty string and short values are excluded by the length floor.
    patterns:
      - pattern-either:
          - pattern: 'let $NAME = "$VAL"'
          - pattern: 'var $NAME = "$VAL"'
      - metavariable-regex:
          metavariable: $NAME
          regex: (?i).*(secret|apikey|api_key|client_secret|token|password|private_key|access_key)
      - metavariable-regex:
          metavariable: $VAL
          regex: '(?i)^(?!.*(?:your[-_]|xxx|placeholder|example|<|\{)).{16,}$'
    paths:
      exclude:
        - "**/test/**"
        - "**/Tests/**"
        - "**/*Tests.swift"
        - "**/*Test.swift"
        - "**/example/**"
        - "**/examples/**"
    metadata:
      oauthlint-rule-id: AUTH-SWIFT-SECRET-001
      oauthlint-doc-url: https://oauthlint.dev/rules/swift-secret-hardcoded-credential
      category: security
      cwe: CWE-798
      owasp: API2:2023
      llm-prevalence: HIGH
      technology:
        - ios
      references:
        - https://developer.apple.com/documentation/security/keychain_services
        - https://cwe.mitre.org/data/definitions/798.html
