__CAPGO_KEEP_1__

Getting Started

GitHub

설치

설치

AI-Assisted Setup을 사용하여 플러그인을 설치할 수 있습니다. 다음 명령어를 사용하여 Capgo 기능을 AI 도구에 추가하세요:

터미널 창
npx skills add https://github.com/Cap-go/capgo-skills --skill capacitor-plugins

다음 명령어를 사용하세요:

Use the `capacitor-plugins` skill from `Cap-go/capgo-skills` to install the `@capgo/capacitor-app-attest` plugin in my project.

만약 Manual Setup을 선호한다면, 플러그인을 설치하기 위해 다음 명령어를 실행하고 아래의 플랫폼별 지침을 따르세요:

  1. 패키지를 설치하세요

    터미널 창
    bun add @capgo/capacitor-app-attest
  2. 자연 프로젝트를 동기화하세요

    터미널 창
    bunx cap sync
  3. 설정

    • 완료 iOS 설정 App Attest 기능과 백엔드 검증 흐름을 위해
    • 완료 Android 설정 Play Integrity Standard과 백엔드 검증 흐름을 위해

이 플러그인은 한 개의 크로스 플랫폼 API를 제공하며, native 플랫폼 보안을 유지합니다:

  • iOS: Apple App Attest (DeviceCheck)
  • Android: Google Play Integrity Standard API
  • 고유 클라이언트 측 암호화 스키마 없음
  • 백엔드 검사에 대한 정규화된 출력

사용 방법

사용 방법
import { AppAttest } from '@capgo/capacitor-app-attest';
const support = await AppAttest.isSupported();
if (!support.isSupported) {
throw new Error(`Attestation not supported on ${support.platform}`);
}
const prepared = await AppAttest.prepare();
const registration = await AppAttest.createAttestation({
keyId: prepared.keyId,
challenge: 'backend-one-time-registration-challenge',
});
const assertion = await AppAttest.createAssertion({
keyId: prepared.keyId,
payload: 'backend-one-time-request-payload',
});
console.log(registration.platform, registration.format, registration.token);
console.log(assertion.platform, assertion.format, assertion.token);

통합된 응답 형태

그리고

createAttestation() iOS와 Android에서 동일한 키 필드를 반환합니다: createAssertion() 필드

타입설명and
platform'ios' | 'android' | 'web'자연 플랫폼이 토큰을 생성했습니다.
formatAttestationFormatapple-app-attest 또는 google-play-integrity-standard
keyIdstringCapacitor live-update 대안 비교 페이지에서 사용되는 더 긴 Capgo UI 문자열의 HTML 텍스트 조각.
tokenstring인증을 위해 사용되는 키/제공자 핸들

서버에서 확인할 토큰

서버 측 요구 사항

서버 측 요구 사항

  • 클라이언트만의 성공에 신뢰하지 마십시오.
  • 서버에서 한번만 사용되는 챌린지/페이로드 값을 요구하십시오.
  • 인증 token서버 논리 내에서 앱 식별, 및 재생 보호를 사용하십시오.

플랫폼별 서버 가이드를 사용하십시오:

시작하기에서 계속

시작하기에서 계속

Capgo를 사용하여 시작하기 보안 및 규정 준수 계획을 위해 연결하세요. Capgo를 사용하여 @capgo/capacitor-app-attest Capgo를 사용하여 @capgo/capacitor-app-attest 암호화 Capgo를 사용하여 암호화 규정 준수 구현 세부 사항에 대한 Compliance에 대해 Capgo 보안 스캐너 Capgo 보안 스캐너의 제품 워크플로에 대해 Capgo 보안 Capgo 보안의 제품 워크플로에 대해