3 ms·
I like Charles and have been using it for this exact purpose for a while now. I'm still wondering what's the best approach from a developer perspective to get a
by Chris911 12y ago
I like Charles and have been using it for this exact purpose for a while now. I'm still wondering what's the best approach from a developer perspective to get around that and keep a private API private. Even if you build a different key for each request on Android you can work your way through obfuscated code and rebuild the logic. If the app requires the user to login running your own OAuth server can be a solution but are there any easier solutions?
- timrogers 12y agoThe short answer is "no" - you're always playing a cat and mouse game, so you're wiser not to put things behind an API that you're really not happy for people to play with. I suspect this is why we've traditionally seen banks (in the UK, at least) use web-pages-embedded-in-apps rather than true native apps.
- alexbilbie 12y agoThe Barclays UK [native] app immediately crashes if you try and pass requests through Charles
- jmgrosen 12y agoHm, do you know how? I'd guess certificate pinning, which would be rather prudent of them, but I'm not sure.
- iancarroll 12y agoIt's probably not detecting the right certificate (or from the right issuer?), yeah. I don't think iOS has an API to see if a proxy is enabled.
- alexbilbie 12y agoBecause I tried...
- kabdib 12y agoYou should expect APIs to be public. For a sufficiently popular service, you should expect people to utterly replace (emulate or rewrite) your fine client and do things that you don't expect, which means implementing things like rate limiting and blacklisting on your server, where you can control things.