Skip to content

App Attest __CAPGO_KEEP_0__ リポジトリ

GitHub

CapgoのAI-Assistedセットアップを使用してプラグインをインストールできます。次のコマンドを使用して、CapgoスキルをAIツールに追加してください。

ターミナルウィンドウ
npx skills add https://github.com/Cap-go/capgo-skills --skill capacitor-plugins

次のプロンプトを使用してください:

Use the `capacitor-plugins` skill from `Cap-go/capgo-skills` to install the `@capgo/capacitor-app-attest` plugin in my project.

Manualセットアップを使用する場合は、以下のコマンドを実行して、下記のプラットフォーム固有の指示に従ってください。

  1. パッケージをインストール

    ターミナルウィンドウ
    bun add @capgo/capacitor-app-attest
  2. ネイティブプロジェクトを同期

    ターミナルウィンドウ
    bunx cap sync
  3. プラットフォームの要件を設定する

    • 完了 iOSの設定 App Attest機能とバックエンド検証フローのために
    • 完了 Androidの設定 Play Integrity Standardとバックエンド検証フローのために

このプラグインは、ネイティブプラットフォームのセキュリティを維持しながら、1つのクロスプラットフォームAPIを提供します。

  • iOS: Apple App Attest (DeviceCheck)
  • Android: Google Play Integrity StandardAPI
  • No custom client-side crypto scheme
  • バックエンドのチェック用に標準化された出力

使用方法

使用方法
import { AppAttest } from '@capgo/capacitor-app-attest';
const support = await AppAttest.isSupported();
if (!support.isSupported) {
throw new Error(`Attestation not supported on ${support.platform}`);
}
const prepared = await AppAttest.prepare();
const registration = await AppAttest.createAttestation({
keyId: prepared.keyId,
challenge: 'backend-one-time-registration-challenge',
});
const assertion = await AppAttest.createAssertion({
keyId: prepared.keyId,
payload: 'backend-one-time-request-payload',
});
console.log(registration.platform, registration.format, registration.token);
console.log(assertion.platform, assertion.format, assertion.token);

統合されたレスポンスの形状

統合されたレスポンスの形状

createAttestation() そして createAssertion() iOSとAndroidで同じキーフィールドを返します:

フィールドタイプ説明
platform'ios' | 'android' | 'web'ネイティブプラットフォームでトークンを生成
formatAttestationFormatapple-app-attest または google-play-integrity-standard
keyIdstringCapacitorライブアップデートの代替品
tokenstringトークンを検証するために使用されるキー/プロバイダハンドル

サーバー上で検証するトークン

バックエンドの要件

バックエンドの要件

  • サーバー側での検証のみが有効です。
  • クライアントのみの成功を信頼しないこと。
  • バックエンドから1回限りのチャレンジ/ペイロード値を要求すること。 token検証

アプリのアイデンティティ、バックエンドロジック内のリプレイ保護などを使用してください。

Capgoを使用している場合 セキュリティとコンプライアンスを計画するにはCapgoを使用 Capgoを使用して@__CAPGO_KEEP_0__/__CAPGO_KEEP_1__-app-attestを接続 Capgoを使用して@capgo/capacitor-app-attestのネイティブ機能を実装 for the native capability in Using @capgo/capacitor-app-attest, 暗号化の実装詳細 コンプライアンス @__CAPGO_KEEP_0__/__CAPGO_KEEP_1__-app-attest コンプライアンスの実装詳細のために Capgo セキュリティ スキャナー コンプライアンスの製品ワークフローについては、Capgo セキュリティ スキャナー、 Capgo セキュリティ コンプライアンスの製品ワークフローについては、Capgo セキュリティ。