Description
Hardcoding public IP addresses in production endpoints or server settings makes infrastructure changes, certificate validation, and network policy enforcement harder. It can also create connections that bypass the intended controls.
Potential impact
- Bypass of network policies for a particular environment.
- Certificate hostname validation failures or additional exceptions.
- Difficulty changing endpoints after deployment.
Remediation
- Manage production destinations through DNS names and environment-specific configuration.
- Keep local development, private network, and documentation example addresses separate from production code.
- Use standard HTTPS endpoints that enforce certificate validation and network policies.
Examples
Before
swift
static let baseURL = "https://34.117.59.81/data"
After
swift
import Foundation
struct AppConfig {
let apiBaseURL: URL
}
func makeRequestURL(config: AppConfig) -> URL {
return config.apiBaseURL.appendingPathComponent("data")
}
Explanation:
- Before: The public IP address is fixed in the code.
- After: The endpoint is managed through configuration for each environment.