Base solution for your next web application
Open Closed

Urgent Support #12611


User avatar
0
smartech created

We are currently working with an Angular and .NET Core application. Our application makes numerous API calls to the backend to retrieve data, and I'm concerned about the visibility of this data in the network traffic—particularly for lookup values and sensitive data elements.

What would be the best approach to secure this data and prevent it from being displayed in clear text over the network in the browser?

Looking forward to your guidance.

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

1 Answer(s)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    Using HTTPS prevents requests and responses from being exposed over the network.

    With HTTPS in place, all API calls between the Angular app and the .NET backend are encrypted, so the data can’t be read in clear text by anyone sniffing the network traffic. This protects against things like proxies, packet-capture tools, and man-in-the-middle attacks.

    You may still see the data in the browser’s Network tab, but that’s normal and expected — the browser needs to decrypt the data in order to use it. From a network security perspective, HTTPS is doing its job.

    As long as HTTPS is enforced everywhere, there’s no risk of the API data being exposed in plain text during transmission.

    See: https://learn.microsoft.com/en-us/aspnet/core/security/enforcing-ssl https://abp.io/docs/latest/deployment/ssl

    Thanks.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)