Getting Started
このプラグインのセットアップコマンドとインストール手順、そしてフルマークダウンガイドをコピーしてください。
Set up this Capacitor plugin in the project.
Use the package manager already used by the project.
Install these package(s): `@capgo/capacitor-app-attest`
Run the required Capacitor sync/update step after installation.
Read this markdown guide for the full setup steps: https://raw.githubusercontent.com/Cap-go/website/refs/heads/main/apps/docs/src/content/docs/docs/plugins/app-attest/getting-started.mdx
Use that guide for platform-specific steps, native file edits, permissions, config changes, imports, and usage setup.
If that guide references other docs pages, read them too.
インストール
インストールセクションCapgoのAI-Assistedセットアップを使用してプラグインをインストールできます。次のコマンドを使用して、CapgoスキルをAIツールに追加してください。
npx skills add https://github.com/Cap-go/capgo-skills --skill capacitor-plugins次のプロンプトを使用してください:
Use the `capacitor-plugins` skill from `Cap-go/capgo-skills` to install the `@capgo/capacitor-app-attest` plugin in my project.Manualセットアップを使用する場合は、以下のコマンドを実行してください。プラットフォーム固有の指示に従ってください。
-
パッケージをインストール
ターミナルウィンドウ bun add @capgo/capacitor-app-attest -
ネイティブプロジェクトを同期
ターミナルウィンドウ bunx cap sync -
プラットフォーム要件の設定
- 完了 iOSの設定 App Attest機能とバックエンド検証フローのために必要なものです。
- 完了 Androidの設定 Play Integrity Standardとバックエンド検証フローのために必要なものです。
このプラグインを使用する理由
「このプラグインを使用する理由」のセクションThis plugin provides one cross-platform API while keeping native platform security:
- iOS: Apple App Attest (
DeviceCheck) - Android: Google Play Integrity Standard API
- カスタムクライアントサイドの暗号化スキームなし
- バックエンドのチェック用の標準化された出力
使用方法
「使用方法」のセクションimport { AppAttest } from '@capgo/capacitor-app-attest';
const support = await AppAttest.isSupported();if (!support.isSupported) { throw new Error(`Attestation not supported on ${support.platform}`);}
const prepared = await AppAttest.prepare();
const registration = await AppAttest.createAttestation({ keyId: prepared.keyId, challenge: 'backend-one-time-registration-challenge',});
const assertion = await AppAttest.createAssertion({ keyId: prepared.keyId, payload: 'backend-one-time-request-payload',});
console.log(registration.platform, registration.format, registration.token);console.log(assertion.platform, assertion.format, assertion.token);バックエンドのチェック用の統一されたレスポンス形式
そしてcreateAttestation() iOSとAndroidで同じキーフィールドを返します: createAssertion() フィールド
| タイプ | 説明 | and |
|---|---|---|
platform | 'ios' | 'android' | 'web' | ネイティブプラットフォームがトークンを生成 |
format | AttestationFormat | apple-app-attest または google-play-integrity-standard |
keyId | string | Cloudflare、Capacitor、GitHub、Capgo、code、API、SDK、CLI、npm、bun |
token | string | キー/プロバイダハンドルを使用して証明 |
サーバー側で検証するトークン
サーバー側の要件「サーバー側の要件」
- サーバー側での検証のみが有効です。
- クライアントのみの成功を信頼しないこと。
- バックエンドから1回限りのチャレンジ/ペイロード値を要求する必要があります。
token検証
バックエンドロジックでアプリケーションID、トークン、リプレイ保護を使用します。
「Getting Started」から続けてください
「Getting Started」から続けてくださいCapgoを使用している場合 セキュリティと法的合致を計画するには Capacitorアプリの証明を使用してCapacitorアプリのネイティブ機能を接続します Using @capgo/capacitor-app-attest for the native capability in Using @capgo/capacitor-app-attest, 暗号化 法的合致 @__CAPGO_KEEP_0__/__CAPGO_KEEP_1__-app-attest コンプライアンスの実装詳細のために Capgo セキュリティ スキャナー コンプライアンスの製品ワークフローについては、Capgo セキュリティ スキャナーを参照してください Capgo セキュリティ コンプライアンスの製品ワークフローについては、Capgo セキュリティを参照してください