The summary.
THE CLIENT CANNOT BE TRUSTED, EVER
Every authorisation decision belongs on the server. Prices, balances and permissions are never determined by the client.
NEVER EMBED SECRETS IN AN APPLICATION
Applications are decompiled routinely and extracting strings is trivial. Obfuscation provides delay, not protection.
Route anything requiring a secret through your own server.
PUT TOKENS AND CREDENTIALS IN SECURE HARDWARE-BACKED STORAGE
Never in preference storage, files or logs. And clear all user data on sign-out — devices are shared.
NEVER DISABLE CERTIFICATE VALIDATION FOR DEVELOPMENT CONVENIENCE
It is frequently left disabled, and it removes all protection.
Weigh certificate pinning carefully — a pinning failure cannot be fixed without a release, and users may not update.
BIOMETRICS CONFIRM PRESENCE, NOT IDENTITY TO YOUR SERVER
The correct pattern is a token in secure storage, released after biometric confirmation. Always provide a fallback.
TREAT DEEP LINK PARAMETERS AS UNTRUSTED INPUT
REVOKE SESSIONS SERVER-SIDE ON SIGN-OUT
Otherwise a stolen token remains valid.