Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What is the problem
On iOS, each request is cached in plain text within the app’s file system. A malicious user with root access could access this cache and extract sensitive data, such as credentials from a login endpoint.
More details on this article
Proposal
Deactivate the URLCache and clear the existing cache
=> Will it break things ? On react native app, caching is mainly done on the JS side, this native cache does not seem to be used
How to reproduce
open $(xcrun simctl get_app_container booted <your.bundle.id> data)
)Library/Caches/<your.bundle.id>
Cache.db
before.mp4
after.mp4
TODO
Blocking the merge:
Experimental
tagTo go further: