Tuesday, December 29, 2020

Tony's Fresh Market app for iOS: Settings menu option has access to staging/prod

 iOS 14.3

Tony's Finer Foods for iOS (version 20201202)

Date: 12/29/2020

Description:

Here's an odd problem! An app for a supermarket chain called "Tony's Finer Foods" has some unusual options in the settings area.

After downloading the app, I spotted this in the Settings area:


An option to select an API Environment and an Asset Environment. I have never seen this before in the settings area for an app, and this most certainly should not have made it through Apple's app store review process. 

Selecting API Environment takes the user here:

The API Environment options include the ability to seemingly toggle between the web environments of Pre/Prod/Staging.


As does the Asset Environment option.

This shouldn't be in accessible in an app for consumers that is downloadable from the app store.

Steps to Reproduce:

1. Download the Tony's Finer Foods app for iOS
2. Head to Settings on the iOS home screen
3. Scroll down to "Tony's Fresh Market"
4. Scroll down to TONY'S FRESH MARKET SETTINGS"

Result: An app on the app store called Tony's Finer Foods has an option in the settings area that seems to allow access to the different back-end environments 

Expected: Apps should not have this accessible 






No comments:

Post a Comment