Android 设置和后端验证
复制安装步骤和本插件的完整 Markdown 指南的设置提示。
Android 原生系统使用
标题为“Android 原生系统使用”在 Android 上,这个插件使用 Google Play Integrity Standard API:
prepareIntegrityToken在prepare()requestStandardIntegrityToken为createAttestation()和createAssertion()
需求
需求- 通过Google Play生态系统发布的Android应用
- 设备上可用的Google Play服务
- 为您的应用启用Play Integrity API
- 已配置的Google Cloud项目号
Google设置
需求- 启用 Play Integrity API 在您的Google Cloud项目中。
- 打开Play Console并为您的应用程序配置Play Integrity访问。
- 提供
cloudProjectNumber给插件
Capacitor配置
标题为“Capacitor配置”plugins: { AppAttest: { cloudProjectNumber: '123456789012', },}您还可以在方法选项中传递 cloudProjectNumber 每次调用
客户端流程
Client 流程import { AppAttest } from '@capgo/capacitor-app-attest';
const { keyId } = await AppAttest.prepare({ cloudProjectNumber: '123456789012',});
const attestation = await AppAttest.createAttestation({ keyId, challenge: 'backend-registration-challenge',});
const assertion = await AppAttest.createAssertion({ keyId, payload: 'backend-request-payload',});token 是一个 Play Integrity 令牌,需要在服务器端解码。
Android 后端工作流
后端工作流 (Android)注册(createAttestation)createAttestation)
后端创建一次性- 应用程序调用
challenge. - 后端调用 Google
createAttestation({ keyId, challenge }). - __CAPGO_KEEP_0__.
decodeIntegrityTokenAPI. - __CAPGO_KEEP_0__.
requestDetails.requestHash === base64url(SHA256(challenge))appIntegrity.packageName与您的Android应用程序ID相同appIntegrity.certificateSha256Digest包含您的发布签名证书摘要- 完整性判决与您的安全策略匹配
请求保护(createAssertion)
标题:请求保护(createAssertion)- 后端创建一次性
payload. - 应用程序调用
createAssertion({ keyId, payload }). - 后端解码令牌并检查
requestHash === base64url(SHA256(payload)). - 强制执行重放防护(单次使用+TTL)和完整性判决策略。
Android模式
标题:Android模式sequenceDiagram participant App as Android App participant Plugin as AppAttest plugin participant PlaySDK as Play Integrity SDK participant BE as Backend participant Google as decodeIntegrityToken API
App->>Plugin: prepare(cloudProjectNumber) Plugin->>PlaySDK: prepareIntegrityToken() PlaySDK-->>Plugin: provider handle (keyId)
BE->>App: one-time challenge App->>Plugin: createAttestation(keyId, challenge) Plugin->>PlaySDK: requestStandardIntegrityToken(requestHash) PlaySDK-->>Plugin: integrity token Plugin-->>App: token + platform + format + keyId App->>BE: token + challenge + keyId BE->>Google: decodeIntegrityToken(token) Google-->>BE: decoded payload BE->>BE: verify requestHash + app identity + verdicts
BE->>App: one-time payload App->>Plugin: createAssertion(keyId, payload) Plugin->>PlaySDK: requestStandardIntegrityToken(requestHash) PlaySDK-->>Plugin: integrity token App->>BE: token + payload + keyId BE->>Google: decodeIntegrityToken(token) Google-->>BE: decoded payload BE->>BE: verify requestHash + replay policy最小后端载荷契约
最小后端载荷契约注册:
{ "platform": "android", "format": "google-play-integrity-standard", "keyId": "string", "challenge": "string", "token": "string"}断言:
{ "platform": "android", "format": "google-play-integrity-standard", "keyId": "string", "payload": "string", "token": "string"}从安卓设置和后端验证继续
从安卓设置和后端验证继续如果您正在使用 安卓设置和后端验证 来规划安全性和合规性,连接它到 使用@capgo/capacitor-app-attest 为使用@capgo/capacitor-app-attest的原生能力 加密 为加密的实现细节 合规 为合规的实现细节 Capgo 安全扫描器 为Capgo 安全扫描器的产品工作流程 Capgo 安全 为Capgo 安全的产品工作流程