package web

import "github.com/xalgord/xalgorix/v4/internal/config"

// reportDisclaimerEN is the English disclaimer printed on the final report
// page. Defined as a const so the report generator and the translation table
// share one canonical source string (guaranteeing the zh-CN lookup matches).
const reportDisclaimerEN = `This penetration test was conducted by Xalgorix, an autonomous AI-powered security assessment tool. The findings in this report are based on automated testing and manual verification where possible.

IMPORTANT NOTICES:

* Scope: This assessment was limited to the target systems explicitly listed in this report. Any systems or services outside the defined scope were not tested.

* False Positives: While Xalgorix attempts to verify findings before reporting, some findings may require manual validation. We recommend validating all critical and high-severity findings before taking remediation actions.

* Limitations: Automated testing cannot discover all vulnerabilities. Manual testing, code review, and other complementary security activities are recommended for comprehensive security coverage.

* Legal: This assessment was conducted with authorization from the target owner. Unauthorized security testing is illegal. Ensure you have proper authorization before testing any system.

* Report Accuracy: This report is provided "as is" without warranties of any kind. The testing methodology and findings are based on the tools and techniques available at the time of testing.

* Remediation: For any vulnerabilities found, follow industry best practices for remediation. Consult with security professionals for complex vulnerabilities.

Generated by Xalgorix - Autonomous AI Pentesting Engine
https://github.com/xalgorix/xalgorix`

// reportTranslations maps a language code to a dictionary keyed by the exact
// English source string used in generateReport. Wrapping the existing literals
// with reportTr(language, "...") localizes the PDF's static labels/headings
// without inventing a separate key scheme. Any string missing from a locale
// falls back to the English source, so partial coverage degrades gracefully.
//
// Only human-readable labels belong here. Values that double as map keys or
// technical tokens (CVE/CWE/OWASP identifiers, CVSS vectors, severities passed
// to the reporting pipeline) must be translated at DISPLAY time only, never at
// their source, so lookups keep working.
var reportTranslations = map[string]map[string]string{
	"zh-CN": {
		// Cover page
		"Security Assessment Report": "安全评估报告",
		"Target":                     "目标",
		"No target recorded":         "未记录目标",
		"not recorded":               "未记录",
		"Status":                     "状态",
		"Risk":                       "风险",
		"Findings":                   "发现",
		"Started":                    "开始时间",
		"SCAN ID":                    "扫描 ID",
		"Autonomous AI-powered security assessment": "由 AI 驱动的自主安全评估",

		// Section headings
		"Executive Summary":              "摘要总览",
		"Risk Assessment":                "风险评估",
		"Scan Details":                   "扫描详情",
		"Testing Methodology":            "测试方法论",
		"Reconnaissance Findings":        "侦察发现",
		"Blue Team Reference Timestamps": "蓝队参考时间戳",
		"Findings Summary":               "漏洞发现汇总",
		"Vulnerability Details":          "漏洞详情",
		"Tested Endpoints & URLs":        "已测试的端点与 URL",
		"Reference Index":                "参考索引",
		"CWE Reference Table":            "CWE 参考表",
		"OWASP Top 10 (2021) Coverage":   "OWASP Top 10 (2021) 覆盖情况",
		"PTES Phase Mapping":             "PTES 阶段映射",
		"Disclaimer":                     "免责声明",

		// Risk / stats card labels
		"OVERALL RISK SCORE": "总体风险评分",

		// Table headers
		"FINDING":        "发现",
		"FINDINGS":       "发现数",
		"FINDING TITLE":  "漏洞标题",
		"SEVERITY":       "严重级别",
		"STATUS":         "状态",
		"CWE NAME":       "CWE 名称",
		"OWASP CATEGORY": "OWASP 类别",
		"PTES PHASE":     "PTES 阶段",
		"TESTED":         "已测试",
		"FOUND":          "发现",

		// Inline labels
		"Method:": "方法：",
		"CVE:":    "CVE：",
		"CVSS:":   "CVSS：",

		// Methodology status + legend
		"Phase %d: %s":                    "阶段 %d：%s",
		"SKIPPED":                         "已跳过",
		"SELECTED":                        "已选择",
		"COMPLETED":                       "已完成",
		"EXECUTED":                        "已执行",
		"NOT APPLICABLE":                  "不适用",
		"BLOCKED":                         "受阻",
		"NOT SELECTED":                    "未选择",
		"PENDING":                         "进行中",
		"= Executed":                      "= 已执行",
		"= Skipped":                       "= 已跳过",
		"= Completed / Executed":          "= 已完成 / 已执行",
		"= Not applicable / Not selected": "= 不适用 / 未选择",
		"= Blocked":                       "= 受阻",

		// Methodology phase names (display only)
		"Deep Reconnaissance & Attack Surface Mapping":             "深度侦察与攻击面测绘",
		"Manual Vulnerability Discovery":                           "人工漏洞挖掘",
		"Directory & File Discovery":                               "目录与文件发现",
		"CORS & Cookie Analysis":                                   "CORS 与 Cookie 分析",
		"Authentication & Session Testing":                         "认证与会话测试",
		"Injection Testing":                                        "注入测试",
		"SSRF Testing":                                             "SSRF 测试",
		"SSRF / Server-Side Request & XML External Entity Testing": "SSRF 服务端请求与 XML 外部实体测试",
		"IDOR & Broken Access Control":                             "IDOR 与访问控制缺陷",
		"API & GraphQL Testing":                                    "API 与 GraphQL 测试",
		"File Upload Testing":                                      "文件上传测试",
		"Deserialization & RCE":                                    "反序列化与 RCE",
		"Race Conditions & Business Logic":                         "竞态条件与业务逻辑",
		"Subdomain Takeover":                                       "子域名接管",
		"Open Redirect Testing":                                    "开放重定向测试",
		"Email Security Testing":                                   "电子邮件安全测试",
		"Cloud & Infrastructure":                                   "云与基础设施",
		"WebSocket Testing":                                        "WebSocket 测试",
		"CMS-Specific Testing":                                     "CMS 专项测试",
		"Broken Link Hijacking & Content Spoofing":                 "失效链接劫持与内容欺骗",
		"Exploit Verification":                                     "漏洞利用验证",
		"Novel Vulnerability Discovery":                            "新型漏洞挖掘",
		"Final Report":                                             "最终报告",

		// PTES phase names (display only — keys stay English)
		"Intelligence Gathering": "情报收集",
		"Vulnerability Analysis": "漏洞分析",
		"Exploitation":           "漏洞利用",
		"Post-Exploitation":      "后渗透",
		"Reporting":              "报告",

		// Paragraphs
		"Xalgorix follows a comprehensive 22-phase penetration testing methodology aligned with OWASP, PTES, and industry best practices. Each phase is executed by an autonomous AI agent with tool access to terminal, browser, and specialized security utilities.": "Xalgorix 遵循全面的 22 阶段渗透测试方法论，与 OWASP、PTES 及行业最佳实践保持一致。每个阶段均由具备终端、浏览器及专用安全工具访问权限的自主 AI 智能体执行。",
		"The following non-exploit reconnaissance observations were extracted from the scan feed and tool outputs. These are included for attack-surface documentation and operational handoff.":                                                                       "以下非利用类侦察观察结果提取自扫描信息流与工具输出，用于攻击面文档记录与运营交接。",
		"The following table summarizes all findings with their security framework mappings (CWE, OWASP Top 10 2021). Detailed write-ups follow in the Vulnerability Details section.":                                                                                 "下表汇总了所有发现及其安全框架映射（CWE、OWASP Top 10 2021）。详细说明见“漏洞详情”章节。",
		"The mappings below are inferred from each finding's vulnerability class and are provided as a consolidated index for traceability and compliance reporting.":                                                                                                  "以下映射根据每项发现的漏洞类别推断得出，作为可追溯性与合规报告的统一索引提供。",

		// Blue Team timestamps
		"The following RFC3339 timestamps enable Blue Team operators to correlate scan activity with SIEM/log sources for use-case development and alert tuning.": "以下 RFC3339 时间戳可帮助蓝队人员将扫描活动与 SIEM/日志源关联，用于用例开发与告警调优。",
		"Scan Start": "扫描开始",
		"Scan End":   "扫描结束",

		// Verification status (format strings — keep %s)
		"Verified via: %s": "验证方式：%s",
		"UNVERIFIED — manual review required (reported via %s)": "未验证 — 需人工复核（通过 %s 报告）",

		// Disclaimer (whole block) — key wired below via init() to reuse the
		// canonical const and avoid drift between the two copies.
	},
}

// init wires the long disclaimer translation using the shared const key so the
// lookup in generateReport (which passes reportDisclaimerEN) always matches.
func init() {
	reportTranslations["zh-CN"][reportDisclaimerEN] = "本次渗透测试由自主 AI 驱动的安全评估工具 Xalgorix 执行。报告中的发现基于自动化测试，并在可能的情况下辅以人工验证。\n\n重要提示：\n\n* 范围：本次评估仅限于报告中明确列出的目标系统。任何超出既定范围的系统或服务均未进行测试。\n\n* 误报：尽管 Xalgorix 会在报告前尝试验证发现，但部分发现可能仍需人工核实。建议在采取修复措施前，验证所有严重和高危级别的发现。\n\n* 局限性：自动化测试无法发现所有漏洞。建议结合人工测试、代码审计及其他补充性安全活动，以实现全面的安全覆盖。\n\n* 法律：本次评估已获得目标所有者的授权。未经授权的安全测试属于违法行为。在测试任何系统前，请确保已获得适当授权。\n\n* 报告准确性：本报告按“现状”提供，不附带任何形式的担保。测试方法与发现基于测试时可用的工具和技术。\n\n* 修复：对于发现的任何漏洞，请遵循行业最佳实践进行修复。对于复杂漏洞，请咨询安全专业人员。\n\n由 Xalgorix 生成 - 自主 AI 渗透测试引擎\nhttps://github.com/xalgorix/xalgorix"
}

// reportTr returns the localized form of an English report label for the given
// language, falling back to the English source when no translation exists.
func reportTr(language, english string) string {
	code := config.NormalizeLanguage(language)
	if code == config.DefaultLanguage {
		return english
	}
	if dict, ok := reportTranslations[code]; ok {
		if translated, ok := dict[english]; ok && translated != "" {
			return translated
		}
	}
	return english
}
