We are currently working with an Angular and .NET Core application. Our application makes numerous API calls to the backend to retrieve data, and I'm concerned about the visibility of this data in the network traffic—particularly for lookup values and sensitive data elements.
What would be the best approach to secure this data and prevent it from being displayed in clear text over the network in the browser?
Looking forward to your guidance.
1 Answer(s)
-
0
hi
Using HTTPS prevents requests and responses from being exposed over the network.
With HTTPS in place, all API calls between the Angular app and the .NET backend are encrypted, so the data can’t be read in clear text by anyone sniffing the network traffic. This protects against things like proxies, packet-capture tools, and man-in-the-middle attacks.
You may still see the data in the browser’s Network tab, but that’s normal and expected — the browser needs to decrypt the data in order to use it. From a network security perspective, HTTPS is doing its job.
As long as HTTPS is enforced everywhere, there’s no risk of the API data being exposed in plain text during transmission.
See: https://learn.microsoft.com/en-us/aspnet/core/security/enforcing-ssl https://abp.io/docs/latest/deployment/ssl
Thanks.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)