Hardcoded public IP addresses in Swift

Hardcoded public IP addresses in Swift

Description

Hardcoding public IP addresses in production endpoints or server settings makes infrastructure changes, certificate validation, and network policy enforcement harder. It can also create connections that bypass the intended controls.

Potential impact

  • Bypass of network policies for a particular environment.
  • Certificate hostname validation failures or additional exceptions.
  • Difficulty changing endpoints after deployment.

Remediation

  1. Manage production destinations through DNS names and environment-specific configuration.
  2. Keep local development, private network, and documentation example addresses separate from production code.
  3. Use standard HTTPS endpoints that enforce certificate validation and network policies.

Examples

Before

swift
static let baseURL = "https://34.117.59.81/data"

After

swift
import Foundation

struct AppConfig {
    let apiBaseURL: URL
}

func makeRequestURL(config: AppConfig) -> URL {
    return config.apiBaseURL.appendingPathComponent("data")
}

Explanation:

  • Before: The public IP address is fixed in the code.
  • After: The endpoint is managed through configuration for each environment.

References