"""A component is a dependency-confusion risk when its normalized name both (a) looks internal
— starts with one of `internal_prefixes` — and (b) already exists on the public index, meaning
an attacker can publish a same-named package there and a misconfigured resolver may prefer it
over the real internal one. Neither condition alone is a finding: an internal-looking name
nobody has published yet is not claimable by anyone today, and a public package whose name only
*contains* the prefix somewhere in the middle (`django-mycorp-plugin`) is not an internal name
at all.
"""
from dataclasses import dataclass

from .graph import build_dependency_graph, reachable_from
from .sbom import load_components


@dataclass(frozen=True)
class ConfusionFinding:
    name: str
    ref: str
    matched_prefix: str
    public_versions: tuple[str, ...]


def normalize_name(name: str) -> str:
    """PyPI (PEP 503) and npm both fold case and treat `-`, `_` and `.` as the same separator
    when resolving a name — `MyCorp_Telemetry`, `mycorp-telemetry` and `mycorp.telemetry` are one
    published project. Compare and index names by this normalized form, never as authored.
    """
    ...


def find_confusion(
    sbom: dict, internal_prefixes: list[str], public_index: dict[str, list[str]]
) -> list[ConfusionFinding]:
    """Every component reachable from the SBOM's root application — not just its *direct*
    dependencies; `requests -> mycorp-billing` is two hops and still counts — whose normalized
    name starts with a normalized entry of `internal_prefixes` AND is a key of `public_index`
    (also compared normalized) becomes one `ConfusionFinding`. `public_versions` is the matched
    `public_index` entry, as a tuple. Return the findings sorted by `name`.
    """
    ...
