Getting Started
이 플러그인의 설치 단계와 전체 마크다운 가이드를 포함한 설정 프롬프트를 복사하세요.
Set up this Capacitor plugin in the project.
Use the package manager already used by the project.
Install these package(s): `@capgo/capacitor-app-attest`
Run the required Capacitor sync/update step after installation.
Read this markdown guide for the full setup steps: https://raw.githubusercontent.com/Cap-go/website/refs/heads/main/apps/docs/src/content/docs/docs/plugins/app-attest/getting-started.mdx
Use that guide for platform-specific steps, native file edits, permissions, config changes, imports, and usage setup.
If that guide references other docs pages, read them too.
설치
설치AI-Assisted Setup을 사용하여 플러그인을 설치할 수 있습니다. 다음 명령어를 사용하여 Capgo 기능을 AI 도구에 추가하세요:
npx skills add https://github.com/Cap-go/capgo-skills --skill capacitor-plugins다음 명령어를 사용하세요:
Use the `capacitor-plugins` skill from `Cap-go/capgo-skills` to install the `@capgo/capacitor-app-attest` plugin in my project.만약 Manual Setup을 선호한다면, 플러그인을 설치하기 위해 다음 명령어를 실행하고 아래의 플랫폼별 지침을 따르세요:
-
패키지를 설치하세요
터미널 창 bun add @capgo/capacitor-app-attest -
자연 프로젝트를 동기화하세요
터미널 창 bunx cap sync -
설정
- 완료 iOS 설정 App Attest 기능과 백엔드 검증 흐름을 위해
- 완료 Android 설정 Play Integrity Standard과 백엔드 검증 흐름을 위해
이 플러그인을 사용하는 이유
이 섹션은 “이 플러그인을 사용하는 이유”입니다.이 플러그인은 한 개의 크로스 플랫폼 API를 제공하며, native 플랫폼 보안을 유지합니다:
- iOS: Apple App Attest (
DeviceCheck) - Android: Google Play Integrity Standard API
- 고유 클라이언트 측 암호화 스키마 없음
- 백엔드 검사에 대한 정규화된 출력
사용 방법
사용 방법import { AppAttest } from '@capgo/capacitor-app-attest';
const support = await AppAttest.isSupported();if (!support.isSupported) { throw new Error(`Attestation not supported on ${support.platform}`);}
const prepared = await AppAttest.prepare();
const registration = await AppAttest.createAttestation({ keyId: prepared.keyId, challenge: 'backend-one-time-registration-challenge',});
const assertion = await AppAttest.createAssertion({ keyId: prepared.keyId, payload: 'backend-one-time-request-payload',});
console.log(registration.platform, registration.format, registration.token);console.log(assertion.platform, assertion.format, assertion.token);통합된 응답 형태
그리고createAttestation() iOS와 Android에서 동일한 키 필드를 반환합니다: createAssertion() 필드
| 타입 | 설명 | and |
|---|---|---|
platform | 'ios' | 'android' | 'web' | 자연 플랫폼이 토큰을 생성했습니다. |
format | AttestationFormat | apple-app-attest 또는 google-play-integrity-standard |
keyId | string | Capacitor live-update 대안 비교 페이지에서 사용되는 더 긴 Capgo UI 문자열의 HTML 텍스트 조각. |
token | string | 인증을 위해 사용되는 키/제공자 핸들 |
서버에서 확인할 토큰
서버 측 요구 사항서버 측 요구 사항
- 클라이언트만의 성공에 신뢰하지 마십시오.
- 서버에서 한번만 사용되는 챌린지/페이로드 값을 요구하십시오.
- 인증
token서버 논리 내에서 앱 식별, 및 재생 보호를 사용하십시오.
플랫폼별 서버 가이드를 사용하십시오:
시작하기에서 계속
시작하기에서 계속Capgo를 사용하여 시작하기 보안 및 규정 준수 계획을 위해 연결하세요. Capgo를 사용하여 @capgo/capacitor-app-attest Capgo를 사용하여 @capgo/capacitor-app-attest 암호화 Capgo를 사용하여 암호화 규정 준수 구현 세부 사항에 대한 Compliance에 대해 Capgo 보안 스캐너 Capgo 보안 스캐너의 제품 워크플로에 대해 Capgo 보안 Capgo 보안의 제품 워크플로에 대해