You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flutter中sign_in_with_apple插件Android端登录失败求助

Android端Apple ID登录(Firebase+sign_in_with_apple)报错解决

问题症状

iOS端登录正常,Android模拟器登录时,在Apple账号验证后出现以下错误:

Unable to process request due to missing initial state. This may happen if browser sessionStorage is inaccessible or accidentally cleared. Some specific scenarios are - 1) Using IDP-Initiated SAML SSO. 2) Using signInWithRedirect in a storage-partitioned browser environment.

核心原因

  1. AndroidManifest未配置回调拦截:Android端依赖Web OAuth流程,未配置intent-filter导致App无法捕获登录回调,sessionStorage中的认证state丢失
  2. 代码中nonce参数处理错误:Android端未传递nonce,不符合Apple和Firebase的安全验证要求

解决方案

1. 配置AndroidManifest.xml

在android/app/src/main/AndroidManifest.xml的主Activity标签内,添加回调URL的intent-filter:

<activity
    android:name=".MainActivity"
    android:exported="true">
    <!-- 保留原有LAUNCHER intent-filter -->
    <intent-filter>
        <action android:name="android.intent.action.MAIN" />
        <category android:name="android.intent.category.LAUNCHER" />
    </intent-filter>

    <!-- 添加Apple登录回调拦截 -->
    <intent-filter>
        <action android:name="android.intent.action.VIEW" />
        <category android:name="android.intent.category.DEFAULT" />
        <category android:name="android.intent.category.BROWSABLE" />
        <!-- 替换为你的Firebase回调URL -->
        <data
            android:scheme="https"
            android:host="your-firebase-project-id.firebaseapp.com"
            android:path="/__/auth/callback" />
    </intent-filter>
</activity>

2. 修复登录代码中的参数处理

调整signInWithApple方法,确保Android端正确传递nonce和rawNonce:

/// Sign In With Apple
signInWithApple() async {
  try {
    String clientID = 'com.example-service'; // 与Apple Service ID一致
    String redirectURL = '[FIREBASE_APPLE_SIGN_IN_RETURN_URL]'; // 替换为实际的Firebase回调URL

    final rawNonce = generateNonce();
    final nonce = sha256ofString(rawNonce);

    final appleCredential = await SignInWithApple.getAppleIDCredential(
      scopes: [
        AppleIDAuthorizationScopes.email,
        AppleIDAuthorizationScopes.fullName,
      ],
      // 所有平台都传递nonce,用于Apple安全验证
      nonce: nonce,
      webAuthenticationOptions: Platform.isIOS
          ? null
          : WebAuthenticationOptions(
              clientId: clientID,
              redirectUri: Uri.parse(redirectURL),
            ),
    );

    final AuthCredential appleAuthCredential = OAuthProvider('apple.com').credential(
      idToken: appleCredential.identityToken,
      // 所有平台都传递rawNonce,用于Firebase验证
      rawNonce: rawNonce,
      accessToken: Platform.isIOS ? null : appleCredential.authorizationCode,
    );

    UserCredential result = await _auth.signInWithCredential(appleAuthCredential);
    User? user = result.user;

    if (user != null) {
      if (result.additionalUserInfo!.isNewUser) {
        await user.delete();
        signOut();
        return Strings.youHaveToSignUpbeforeSignInWithApple;
      }
      return _userFromFireBaseUser(user);
    }
    return null;
  } catch (e) {
    rethrow;
  }
}

3. 验证模拟器浏览器设置

确保模拟器默认浏览器允许访问sessionStorage:

  • 打开Chrome浏览器,进入「设置-隐私和安全」,关闭「阻止第三方Cookie」选项
  • 优先使用系统默认浏览器测试,避免自定义浏览器的隐私限制

关键说明

  • Android端Apple登录依赖Web跳转,必须配置intent-filter才能让App接收认证回调,否则会丢失state导致报错
  • nonce是防重放攻击的核心机制,Apple和Firebase都需要验证其一致性,不能仅在iOS端传递
  • 回调URL必须与Firebase后台配置的完全一致,包括协议、域名和路径

内容的提问来源于stack exchange,提问作者MrOrhan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 00:23:20