Enable CORS in all environments and disable HTTPS redirect in dev. Seed the database after migrations. Make the API base URL configurable, defaulting to the Android emulator host, and use per-config Android manifests.