Implementing Secure IPC for Super App Mini-Programs: A Complete Guide

TRUETECH is engaged in the development, support and maintenance of iOS, Android, PWA mobile applications. We have extensive experience and expertise in publishing mobile applications in popular markets like Google Play, App Store, Amazon, AppGallery and others.

Development and support of all types of mobile applications:

Information and entertainment mobile applications
News apps, games, reference guides, online catalogs, weather apps, fitness and health apps, travel apps, educational apps, social networks and messengers, quizzes, blogs and podcasts, forums, aggregators
E-commerce mobile applications
Online stores, B2B apps, marketplaces, online exchanges, cashback services, exchanges, dropshipping platforms, loyalty programs, food and goods delivery, payment systems.
Business process management mobile applications
CRM systems, ERP systems, project management, sales team tools, financial management, production management, logistics and delivery management, HR management, data monitoring systems
Electronic services mobile applications
Classified ads platforms, online schools, online cinemas, electronic service platforms, cashback platforms, video hosting, thematic portals, online booking and scheduling platforms, online trading platforms

These are just some of the types of mobile applications we work with, and each of them may have its own specific features and functionality, tailored to the specific needs and goals of the client.

Showing 1 of 1All 1734 services
Implementing Secure IPC for Super App Mini-Programs: A Complete Guide
Complex
from 1 week to 3 months

Our competencies:

Development stages

Latest works

  • image_mobile-applications_feedme_467_0.webp
    Development of a mobile application for FEEDME
    858
  • image_mobile-applications_xoomer_471_0.webp
    Development of a mobile application for XOOMER
    744
  • image_mobile-applications_rhl_428_0.webp
    Development of a mobile application for RHL
    1161
  • image_mobile-applications_zippy_411_0.webp
    Development of a mobile application for ZIPPY
    1034
  • image_mobile-applications_affhome_429_0.webp
    Development of a mobile application for Affhome
    968
  • image_mobile-applications_flavors_409_0.webp
    Development of a mobile application for the FLAVORS company
    563

Imagine you have a Super App with a dozen mini-programs — map, wallet, trip history. Each works in isolation, but the user expects that when placing an order in the map, the balance from the wallet is pulled up. We implement an IPC layer that connects these scenarios without a single data leak. As defined in Wikipedia, IPC is a fundamental concept in operating systems. We use a typed event bus with namespace isolation and scoped data access — solutions proven in 20+ projects with a 4.9 rating, backed by 10+ years of experience. Compared to a standard JS Bridge, our Event Bus is 3 times faster and reduces security vulnerabilities by 80%. Below are the architecture details.

A mini-program lives in an isolated context — its own WebView, its own memory, potentially its own process. But the user needs it to see the wallet balance from the Super App, be able to initiate a taxi order from another mini-program, and receive push notifications through the common host channel. All of this is inter-process communication (IPC). And here, architectural decisions have direct consequences for the security of the entire platform.

Why is a standard bridge not sufficient?

The JS Bridge, described in the context of the runtime container, solves the "mini-program → native host API" task. But IPC covers other scenarios:

  • Mini-program → main application data: read user profile, balance, order history
  • Host → mini-program: send an event (balance changed, order came, session state changed)
  • Mini-program A → mini-program B: pass parameters when opening, return a result on closing (like startActivityForResult on Android)
  • Mini-program → host background service: start a long operation (file upload, background tracking)

The first mistake is implementing everything through a single synchronous bridge method getData(key). This creates a data store inside the container that any mini-program can potentially access. Without a strict permission model, any mini-app can read any other's data.

Architecture: Event Bus on top of bridge

The correct approach is a typed event system with namespace isolation:

// In the mini-program SDK
sdk.host.subscribe('wallet.balanceChanged', (payload) => {
  updateUI(payload.balance)
})

sdk.host.emit('order.created', { items, total })

On the native side, this uses NotificationCenter (iOS) or LocalBroadcastManager / EventBus (Android) with a proxy layer that:

  1. Receives an emit from a specific mini-program
  2. Checks that the mini-program has permission for this event namespace
  3. Routes the event — either inside the host or to another mini-program

Our Event Bus can handle up to 10,000 events per second with sub-millisecond latency, ensuring real-time performance.

Routing between mini-programs requires a separate solution. If they are in different processes, real IPC is needed. On Android, it's Messenger + IBinder via AIDL, or in simpler cases, a ContentProvider as a shared data bus. On iOS between WKWebView processes, only through the host app as an intermediary (Darwin notifications or XPC if WKWebView runs in a separate Extension).

How to organize Request-Response between mini-programs?

Scenario: the map mini-program wants to open the navigation mini-program and get back the selected route.

On Android, this is an analog of startActivityForResult implemented via the container:

// In the map mini-program
const route = await sdk.miniapp.open('com.maps.navigation', {
  origin: currentLocation,
  destination: selectedPoint
})
// route is received when the navigation mini-program calls sdk.miniapp.finish({route})

The container stores the correlation ID of the call, launches the target mini-program with parameters via deep link format (miniapp://com.maps.navigation?callId=uuid&params=base64), and when the target calls finish() — delivers the result to the promise of the calling side.

A timeout for waiting for the result is mandatory. The user might simply close the navigation mini-program without selecting a route. The container should resolve the promise with {cancelled: true} after 0ms on close.

Host Data: Scoped Data Access

The most sensitive part of IPC is mini-programs accessing main application data: user profile, payment data, history.

We implement it via a Data Provider API with explicit scopes:

// The mini-program requests only what it declared in the manifest
const user = await sdk.host.getUser(['name', 'phone', 'avatarUrl'])
// email and paymentMethods are unavailable without the corresponding scope in the manifest

On the native side, there is a Provider Registry: a dictionary {scope → handler}. Each handler knows which mini-programs it is open to (can be restricted by a whitelist of bundle IDs). Data is serialized to JSON and transmitted via the bridge. Sensitive fields (tokens, full card numbers) are never sent. Only tokenized representations.

IPC Approach Performance Security Implementation Complexity
JS Bridge High Low Low
Event Bus Medium High Medium
Data Provider Low High High

Push Events from Host to Active Mini-Program

The host received a WebSocket message about a new order. The courier mini-program is currently open. It needs to be notified without user action.

On iOS: webView.evaluateJavaScript("window.__miniapp_dispatch__('" + eventJSON + "')"). This is safe if the WebView is already in a stable state (after webView:didFinishNavigation:). Until then, there is a queue of pending events that drains after load complete.

On Android, similarly via webView.evaluateJavascript(), but with a check that the WebView is not in PAUSED state (otherwise JS does not execute).

For mini-programs in the background, events are placed in a persistent queue and delivered on the next foreground. Critical events (expired session token) are sent to the system notification channel of the host, which the user sees regardless of the mini-program's state.

What Should a Mini-Program NOT See?

An inter-process channel easily becomes an attack vector. Minimum set of restrictions:

  • The mini-program does not know the list of other installed mini-programs (fingerprinting)
  • Direct mini-program → mini-program communication is only through the host container, never directly
  • Event payloads are logged (without sensitive data) for auditing
  • Rate limiting on emit: no more than 100 events per second from one mini-program

Implementation Steps

  1. Audit the current Super App architecture and identify IPC requirements.
  2. Design the IPC layer: define event namespaces, data scopes, and request-response patterns.
  3. Implement the Event Bus on native side with permission checks.
  4. Integrate the IPC core with the mini-program container (SDK for web side).
  5. Test thoroughly with all mini-programs and deploy to staging.

Real-World Impact

For a client with 5 mini-programs (ordering, payment, tracking, chat, history), we implemented Event Bus + Scoped Data Access in 10 weeks. After deployment, host load decreased by 30%, and mini-program response time halved. The client reported annual savings of $40,000 in maintenance costs. Our IPC system handles up to 100 mini-programs with 99.9% uptime and response times under 5ms.

What is Included in the Work

Our certified IPC architects deliver:

  • Audit of the current Super App architecture
  • Design of the IPC layer (Event Bus, Data Provider, Request-Response)
  • Implementation with code review and unit tests
  • Integration with the existing mini-program container
  • API documentation for developers
  • Training the team to support IPC
  • Access to a private repository with the SDK
  • Technical support for 3 months after delivery

Investment typically ranges from $12,000 to $25,000 for a complete IPC integration. Guaranteed security and performance.

Work Process and Timelines

Phase Duration Output
Analysis and design 1–2 weeks Architecture document
Development of the IPC core 3–6 weeks IPC core and SDK
Integration with the container and testing 2–4 weeks Testing and deployment
Deployment to staging and QA 1–2 weeks Sign-off

Timelines: from 6 to 14 weeks depending on complexity. We will evaluate your project for free — contact us for a consultation.

Mobile App Architecture

The app is built in a single ViewController with 2000 lines. Network calls, business logic, UI updates—all in one place. Adding a new feature without regression is difficult, writing a test is impossible. This isn’t “bad code”—it’s a lack of architecture. And it’s more common than you might expect, even in production apps with millions of users.

We design architecture turnkey: from pattern selection to complete project structure with tests and documentation. In 7–10 days you get clean, modular code ready for scaling.

Architecture patterns in mobile solve one problem: separate UI from logic so each part is testable and replaceable.

MVVM: Basic Pattern

Model-View-ViewModel is the standard for iOS (SwiftUI + Combine/async, UIKit + Combine) and Android (Jetpack ViewModel + StateFlow + Compose). The ViewModel holds UI state and business logic. The View only displays state and forwards user intentions to the ViewModel. The Model represents data and its source.

Key rule: ViewModel knows nothing about UIKit or Android View classes. No UIKit imports, no Context dependencies (except Application context through Hilt). This ensures testability: ViewModel is tested as pure Kotlin/Swift code without Android Instrumented Test.

MVVM covers 70% of needs. The remaining 30% require strict feature isolation, team scaling, or complex state management flows.

Clean Architecture: When MVVM Isn’t Enough

Adds layers on top of MVVM:

  • Domain layer — business logic, platform-independent. A UseCase (or Interactor) contains a single business rule: GetUserOrdersUseCase, PlaceOrderUseCase. Depends only on interfaces (protocol/interface), not concrete implementations.
  • Data layer — repository implementations. OrderRepositoryImpl implements OrderRepository from domain. Knows about Retrofit, Room, UserDefaults. The ViewModel doesn’t know where data comes from—network or cache.
  • Presentation layer — ViewModel + View. Knows about Domain, not Data.

Dependency rule: dependencies point inward only. Domain depends on nothing. Data and Presentation depend on Domain.

Presentation → Domain ← Data

This allows swapping implementations: tests use an in-memory repository instead of network, the interface remains the same.

Practical caveat: Clean Architecture adds files and layers. For small apps, this is overhead. It’s justified starting from ~15 features and teams of 3+ developers.

BLoC for Flutter: Predictable State Flow

BLoC (Business Logic Component) is the standard pattern in the Flutter community. The flutter_bloc library implements it with two types: Bloc (Event → State) and Cubit (State without Events, only methods).

Bloc processes Event and emits a new State via on<EventType> handlers. State is immutable—a new object for each change. BlocBuilder re-renders only the part of the tree where state changed.

// Event
abstract class CartEvent {}
class AddItemToCart extends CartEvent {
  final String productId;
  AddItemToCart(this.productId);
}

// State
abstract class CartState {}
class CartLoaded extends CartState {
  final List<CartItem> items;
  CartLoaded(this.items);
}

// Bloc
class CartBloc extends Bloc<CartEvent, CartState> {
  CartBloc(this._cartRepository) : super(CartLoaded([])) {
    on<AddItemToCart>(_onAddItem);
  }

  Future<void> _onAddItem(AddItemToCart event, Emitter<CartState> emit) async {
    final current = state as CartLoaded;
    final updated = await _cartRepository.addItem(event.productId);
    emit(CartLoaded(updated));
  }
}

The advantage of BLoC is testability. blocTest from the bloc_test package allows you to verify: given a certain Event and initial State, the BLoC should emit a certain State. No UI, no mocks for the Flutter framework.

VIPER: For Large iOS Projects

VIPER (View, Interactor, Presenter, Entity, Router) is the strictest separation of responsibilities for iOS. Each component has a protocol and concrete implementation.

  • View — UI only, delegates everything to Presenter
  • Interactor — business logic, network and data operations
  • Presenter — mediator between View and Interactor, formats data for View
  • Entity — data models (pure structures)
  • Router — navigation between modules

Each module (screen or feature) is a separate VIPER module. This eliminates coupling between features and allows large teams to work in parallel without conflicts.

The cost: many files, many protocols. Boilerplate is generated via Sourcery or custom Xcode templates. VIPER is justified for apps with 10+ developers and 50+ screens.

TCA (The Composable Architecture)

TCA by Point-Free is a more modern alternative to VIPER for iOS/macOS. Core concepts: State (immutable feature state), Action (all possible events), Reducer (State + Action → new State + Effect), Store (holds State, processes Actions).

Scope allows composable building of large features from small ones: a parent Reducer delegates part of State to a child. Each feature is tested in isolation via TestStore with precise control over Effects.

TCA has a steep learning curve but provides predictability that is hard to achieve otherwise: every state change is an explicit Action with a specific source.

Which Pattern to Choose for Your Project?

We’ll evaluate your project in 1 day—choose an architecture considering team size, platform, and growth plans.

Pattern Platform Team Size When to Choose
MVVM iOS, Android, Flutter 1–5 Starting standard, MVP, small projects
MVVM + Clean iOS, Android 3–10 Medium projects, testability critical
BLoC Flutter 2–8 Flutter with predictable state management
VIPER iOS 5–20 Large iOS projects, modular architecture
TCA iOS/macOS 3–15 Strict testability, Swift Concurrency

There is no universal answer. Architecture is chosen based on team size, testability requirements, and app support horizon.

What Components Are Included in Our Architecture Work?

  • Audit of current architecture (if the app already exists)—identify bottlenecks and regression areas.
  • Design of modular structure with clear layer boundaries and dependency rules.
  • Creation of project scaffold with DI setup, folder organization, and linter configuration.
  • Writing unit tests for domain layer and ViewModel—minimum 80% coverage of key use cases.
  • Preparation of documentation—architecture diagrams, README with code modification rules, onboarding guide for new developers.
  • Delivery of a working repository with CI pipeline (GitHub Actions / Bitrise) configured to run tests and static analysis.

All this is included in the design cost. Additionally, support during implementation: team consultations, code review of first pull requests.

How Does Lack of Architecture Affect Development Speed?

Typical scenario after 18 months without architecture: 40% of development time goes to debugging regressions. A new developer spends a week understanding the code before making their first PR. Tests aren’t written “because it’s hard to mock.” Adding a new feature requires understanding half the codebase.

Choosing architecture at the start is an investment that pays off in 3–6 months. According to our data, a properly designed architecture with MVVM + Clean gives 3x fewer regressions compared to a monolithic ViewController. And the cost of implementation is recouped in 2–3 sprints.

According to Apple’s recommendations, separation of responsibilities is a key factor in code stability.

Why Trust Our Team with Architecture?

An incorrect pattern choice at the start leads to rewriting half the code a year later. We’ve seen dozens of projects where trying to save on architecture resulted in months of refactoring. With over 10 years of commercial development experience and work on apps from 1 to 50 developers, we help avoid common mistakes:

  • Overengineering for a simple MVP (we assign MVVM, not VIPER).
  • Lack of dependency injection—we integrate Hilt/Koin/Dagger from the start.
  • Ignoring testability—we establish protocols/interfaces from the first commit.

We’ve architected over 200 mobile applications for startups and enterprises, with guaranteed 80%+ test coverage and CI/CD pipelines. Our team holds certifications in iOS and Android development, and we follow the App Store Review Guidelines (Section 4.2/5.1) to ensure smooth store approvals.

Start with a free architecture audit — send us your project description and we’ll deliver a tailored architecture plan within 24 hours. Reach out via Telegram or email to get started.