En Ionic 3 tenemos a nuestra disposición la clase HTTP, que no es la misma que la clase http de Angular, la cual pertenece a Ionic Native y se importa desde @ionic-native/http.
La funcionalidad de la clase HTTP de Ionic Native y la clase Http en Angular 2 es prácticamente la misma, pero con una diferencia muy importante, el método enableSSLPinning. ¿Qué significa SSL Pinning? A groso modo podemos decir que es una técnica en la que se fija el certificado SSL o la clave pública del servidor en el teléfono, con lo cual conseguimos un canal seguro entre el servidor y la aplicación, cosa que no pasa con el mero hecho de utilizar SSL, ya que en ningún momento sabemos si las peticiones las hace quien realmente las debe hacer.
Un artículo muy interesante lo tienes aquí, te lo recomiendo. ¿Cómo utilizar SSL Pinning en Ionic? El valor predeterminado es false, para utilizar SSL Pinning, debemos incluir al menos un certificado SSL .cer en el proyecto de la aplicación.
Puedes establecer un pin en el certificado de servidor o en uno de los certificados de CA emisores.
Para iOS deberás incluir el certificado en la raíz del package (simplemente añade el archivo .cer a la raíz de tu proyecto).
Para android deberás incluir el certificado en el directorio /platforms/android/assets del proyecto.
Como alternativa, podemos almacenar los archivos .cer en la carpeta www/certificates y también funcionará.
A continuación tienes la clase HTTP de Ionic para que veas qué podemos hacer con ella.
/**
* This returns an object representing a basic HTTP Authorization header of the form.
* @param username {string} Username
* @param password {string} Password
* @returns {Object} an object representing a basic HTTP Authorization header of the form {'Authorization': 'Basic base64encodedusernameandpassword'}
*/
getBasicAuthHeader(username: string, password: string): {
Authorization: string;
};
/**
* This sets up all future requests to use Basic HTTP authentication with the given username and password.
* @param username {string} Username
* @param password {string} Password
*/
useBasicAuth(username: string, password: string): void;
/**
* Set a header for all future requests. Takes a header and a value.
* @param header {string} The name of the header
* @param value {string} The value of the header
*/
setHeader(header: string, value: string): void;
/**
* Enable or disable SSL Pinning. This defaults to false.
*
* To use SSL pinning you must include at least one .cer SSL certificate in your app project. You can pin to your server certificate or to one of the issuing CA certificates. For ios include your certificate in the root level of your bundle (just add the .cer file to your project/target at the root level). For android include your certificate in your project's platforms/android/assets folder. In both cases all .cer files found will be loaded automatically. If you only have a .pem certificate see this stackoverflow answer. You want to convert it to a DER encoded certificate with a .cer extension.
*
* As an alternative, you can store your .cer files in the www/certificates folder.
* @param enable {boolean} Set to true to enable
* @returns {Promise<void>} returns a promise that will resolve on success, and reject on failure
*/
enableSSLPinning(enable: boolean): Promise<void>;
/**
* Accept all SSL certificates. Or disabled accepting all certificates. Defaults to false.
* @param accept {boolean} Set to true to accept
* @returns {Promise<void>} returns a promise that will resolve on success, and reject on failure
*/
acceptAllCerts(accept: boolean): Promise<void>;
/**
* Whether or not to validate the domain name in the certificate. This defaults to true.
* @param validate {boolean} Set to true to validate
* @returns {Promise<void>} returns a promise that will resolve on success, and reject on failure
*/
validateDomainName(validate: boolean): Promise<void>;
/**
* Make a POST request
* @param url {string} The url to send the request to
* @param body {Object} The body of the request
* @param headers {Object} The headers to set for this request
* @returns {Promise<HTTPResponse>} returns a promise that resolve on success, and reject on failure
*/
post(url: string, body: any, headers: any): Promise<HTTPResponse>;
/**
*
* @param url {string} The url to send the request to
* @param parameters {Object} Parameters to send with the request
* @param headers {Object} The headers to set for this request
* @returns {Promise<HTTPResponse>} returns a promise that resolve on success, and reject on failure
*/
get(url: string, parameters: any, headers: any): Promise<HTTPResponse>;
/**
*
* @param url {string} The url to send the request to
* @param body {Object} The body of the request
* @param headers {Object} The headers to set for this request
* @param filePath {string} The local path of the file to upload
* @param name {string} The name of the parameter to pass the file along as
* @returns {Promise<HTTPResponse>} returns a promise that resolve on success, and reject on failure
*/
uploadFile(url: string, body: any, headers: any, filePath: string, name: string): Promise<HTTPResponse>;
/**
*
* @param url {string} The url to send the request to
* @param body {Object} The body of the request
* @param headers {Object} The headers to set for this request
* @param filePath {string} The path to donwload the file to, including the file name.
* @returns {Promise<HTTPResponse>} returns a promise that resolve on success, and reject on failure
*/
downloadFile(url: string, body: any, headers: any, filePath: string): Promise<HTTPResponse>;