أهداف الدرس
- أن تعرف قواعد الاتصال الآمن من الهاتف.
- كل اتصال مشفّر، دون استثناء.
- بيانات الدخول في التخزين الآمن للنظام، لا في التخزين العادي.
- لا أسرار داخل التطبيق نفسه؛ يمكن فكّه وقراءته.
- حين ينتهي الدخول، عُد إلى شاشة الدخول بلطف.
كل ما في التطبيق يراه من يفكّه؛ الحماية الحقيقية على الخادم.
تمرين
ماذا تفعل إن رفض الخادم الطلب لأن الدخول انتهى؟
الإجابة
تجدّد الدخول مرة واحدة، فإن فشل تعيد المستخدم إلى شاشة الدخول.
Lesson goals
- Know the rules of safe calls from a phone.
- Every connection is encrypted, no exceptions.
- Sign-in data lives in the system's secure storage, not plain storage.
- No secrets inside the app itself; it can be unpacked and read.
- When a sign-in ends, return to the sign-in screen gracefully.
Anything inside the app can be seen by whoever unpacks it; real protection lives on the server.
Exercise
What do you do if the server refuses because the sign-in expired?
Answer
Renew the sign-in once; if that fails, send the user back to sign-in.
التعليقات / Comments
لا تعليقات بعد. كن أول من يسأل. / No comments yet. Be the first to ask.