Looking for someone to help dissect an app. Or a group effort.
I dont know how legal this is, but this is the app they are using to scan the vax passes in canada. Having a look under the hood would be cool, at the least.
Thinking out loud.
The app presumably looks to server for the information or verification.
Can a redirect be done, to local host, with a return "pass" message spoofed locally on the device?