I am building an app which gets JSON-encoded data from a web server. Right now, anyone can access the server-script that gets the data, and potentially access sensitive data.
So, what is the best way to ensure that the app is what's getting the data, and secure the traffic between the server and app? The server-script is PHP.
Thank you.