I'm currently working on an Android app that has been architected to connect directly to an AWS RDS MariaDB instance.
We realize this architecture is not correct, the three main issues with this approach are:
- The database will have to be exposed to the Internet
- The database credentials are stored in the Android app
- The client Android app is trusted to send SQL queries directly into RDS
We know we need an online interface between our Android app and our RDS instance to:
Remove database credentials from the Android app and place them in the online interface
Control the queries going to the database by validating the client query (i.e. low level users can not delete tables) before executing it
What we don't know is how to convert our working (but unsafe and amateur) direct RDS SQL queries, into API calls or validated queries with the least amount of resitance. We want to utilize AWS where it makes the most sense, but we're open to any best-practice-based approach if more suitable.
I may be naive, and perhaps I'm looking for a solution that does not exist, but given that we already have all of the working SQL queries and schema my brain is searching for a semi-automated approach that converts the SQL logic to restful API calls. Or, is there a service that provides user authentication directly from an Android app (users will have to sign in to connect to the online interface I assume) and validates SQL queries to a MariaDB RDS instance?
Thank you kindly for pushing me in the right direction!
TL;DR - Android app connects via in-app credentials directly to the MariaDB AWS RDS instance and users write SQL queries directly to it from all over the Internet... This is bad. What's the least resistant method to convert this approach to users authenticating with a middle-man online interface which validates their changes and posts to a MariaDB instance?