You can also click a link to a certificate on a webpage and install it manually on iOS.
2. You have to trust the Charlesproxy root certificate; again, in the system settings.
Charles desktop app is well respected in the developer community. There is no reason that the iOS app will be treated any differently.
How exactly does one go about patching the binary – is there a tutorial somewhere?
Yes
>How exactly does one go about patching the binary – is there a tutorial somewhere?
https://www.guardsquare.com/en/blog/iOS-SSL-certificate-pinn...
There are guides you can google for cracking apps and replacing the certs they compare against. IIRC they all require a jailbroken device.
[1] https://developer.apple.com/library/content/releasenotes/Gen...
[0] Of course you can use the blanket NSAllowsArbitraryLoads to allow plain HTTP everywhere.
Under what conditions does iOS allow an app to do this?