Android Kotlin Credential Manager:如何启用PublicKeyCredential与PasswordCredential
关于PublicKeyCredential和PasswordCredential的作用及启用方式
一、两种Credential的作用
1. PublicKeyCredential
这是用于WebAuthn/FIDO2无密码登录的凭证类型,基于公钥加密实现身份验证。authenticationResponseJson包含公钥验证所需的核心数据(如签名、用户凭证ID等),需将该JSON发送至后端,用对应公钥完成身份校验,实现免密码的安全登录。
2. PasswordCredential
对应系统保存的账号密码凭证,当用户授权系统记住密码后,该类型会返回已保存的用户名和密码。拿到username和password后,需将其发送至服务端做校验与认证,本质是调用系统自动填充的密码完成登录流程。
二、启用两种Credential的配置方式
你当前的请求仅配置了Google ID Token,需在GetCredentialRequest.Builder中添加对应选项才能启用另外两种凭证:
1. 启用PasswordCredential
直接添加PasswordCredentialOption即可,无需额外参数:
val passwordOption = PasswordCredentialOption.Builder().build() val request: GetCredentialRequest = GetCredentialRequest.Builder() .addCredentialOption(googleIdOption) .addCredentialOption(passwordOption) // 加入密码凭证选项 .build()
2. 启用PublicKeyCredential
需创建GetPublicKeyCredentialOption,配置后端生成的挑战值(challenge)等核心参数,示例如下:
// 挑战值需从后端获取,为WebAuthn流程必填项 val challenge = "backend_generated_challenge_string" val publicKeyOption = GetPublicKeyCredentialOption.Builder(challenge) .setRpId("your_application_domain.com") // 需与后端配置的域名一致 .build() val request: GetCredentialRequest = GetCredentialRequest.Builder() .addCredentialOption(googleIdOption) .addCredentialOption(publicKeyOption) // 加入公钥凭证选项 .build()
注意:PublicKeyCredential的启用依赖后端WebAuthn服务配置,挑战值必须由后端动态生成下发,不能硬编码,否则无法完成验证流程。
三、测试注意事项
- PasswordCredential需要用户此前已在系统中保存过对应应用/网站的账号密码,才会返回该类型凭证。
- PublicKeyCredential需要用户已完成WebAuthn注册流程(即创建过公钥凭证),且后端正确配置WebAuthn服务,才能在登录时触发。
内容的提问来源于stack exchange,提问作者TheGreatCornholio
相关产品推荐
相关产品推荐

