You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

React Native应用中使用Firebase电话认证时如何规避reCAPTCHA验证?

React Native集成Google Play Integrity API 规避reCAPTCHA验证方案

一、先排查react-native-firebase/app-check失效原因

  • 确认Firebase项目已将Play Integrity设为App Check的提供者(SafetyNet已弃用,需切换)
  • 检查Android端配置:
    • 确保google-services.json是最新版本,包含Play Integrity相关配置项
    • android/build.gradle中Google服务插件版本不低于4.3.15
    • android/app/build.gradle添加依赖:
      implementation "com.google.android.play:integrity:1.1.0"
      
  • 验证初始化代码顺序:App Check必须在Firebase初始化后调用
    import firebase from '@react-native-firebase/app';
    import appCheck from '@react-native-firebase/app-check';
    
    firebase.initializeApp();
    
    appCheck().initializeAppCheck({
      provider: appCheck.PlayIntegrityProvider,
      // 调试模式下填写调试令牌,生产环境移除该配置
      debugToken: '你的调试令牌',
    });
    

二、直接集成Play Integrity原生SDK(绕开Firebase App Check)

如果Firebase方案仍不生效,可通过React Native原生桥接直接调用Play Integrity API:

Android端实现

  1. 在android/app/build.gradle添加依赖:
    implementation "com.google.android.play:integrity:1.1.0"
    
  2. 创建原生模块PlayIntegrityModule.java:
    package com.yourappname;
    
    import com.facebook.react.bridge.ReactApplicationContext;
    import com.facebook.react.bridge.ReactContextBaseJavaModule;
    import com.facebook.react.bridge.ReactMethod;
    import com.facebook.react.bridge.Promise;
    import com.google.android.play.core.integrity.IntegrityManager;
    import com.google.android.play.core.integrity.IntegrityManagerFactory;
    import com.google.android.play.core.integrity.IntegrityTokenRequest;
    import com.google.android.play.core.integrity.IntegrityTokenResponse;
    import com.google.android.play.core.tasks.Task;
    import com.google.android.play.core.tasks.Tasks;
    
    public class PlayIntegrityModule extends ReactContextBaseJavaModule {
      private final IntegrityManager integrityManager;
    
      public PlayIntegrityModule(ReactApplicationContext reactContext) {
        super(reactContext);
        integrityManager = IntegrityManagerFactory.create(reactContext);
      }
    
      @Override
      public String getName() {
        return "PlayIntegrity";
      }
    
      @ReactMethod
      public void requestIntegrityToken(String nonce, Promise promise) {
        IntegrityTokenRequest request = IntegrityTokenRequest.builder()
          .setNonce(nonce)
          .setCloudProjectNumber(1234567890) // 替换为你的Google Cloud/Firebase项目编号
          .build();
    
        Task<IntegrityTokenResponse> task = integrityManager.requestIntegrityToken(request);
        try {
          IntegrityTokenResponse response = Tasks.await(task);
          promise.resolve(response.token());
        } catch (Exception e) {
          promise.reject("PLAY_INTEGRITY_ERROR", e.getMessage());
        }
      }
    }
    
  3. 在MainApplication.java注册模块:
    import com.yourappname.PlayIntegrityModule;
    // ...
    @Override
    protected List<ReactPackage> getPackages() {
      List<ReactPackage> packages = new PackageList(this).getPackages();
      packages.add(new ReactPackage() {
        @Override
        public List<NativeModule> createNativeModules(ReactApplicationContext reactContext) {
          List<NativeModule> modules = new ArrayList<>();
          modules.add(new PlayIntegrityModule(reactContext));
          return modules;
        }
    
        @Override
        public List<ViewManager> createViewManagers(ReactApplicationContext reactContext) {
          return Collections.emptyList();
        }
      });
      return packages;
    }
    

React Native端调用

import { NativeModules } from 'react-native';
const { PlayIntegrity } = NativeModules;

// 生成随机nonce(建议由后端生成,避免重放攻击)
const generateNonce = () => {
  return Math.random().toString(36).substring(2, 15) + Math.random().toString(36).substring(2, 15);
};

// 请求完整性令牌
const getIntegrityToken = async () => {
  try {
    const nonce = generateNonce();
    const token = await PlayIntegrity.requestIntegrityToken(nonce);
    // 将令牌发送到后端验证
    console.log('Integrity Token:', token);
    return token;
  } catch (error) {
    console.error('Play Integrity调用失败:', error);
  }
};

三、后端令牌验证

拿到令牌后,必须在后端完成验证:

  • 使用Google Cloud服务账号密钥,调用https://playintegrity.googleapis.com/v1/{packageName}:decodeIntegrityToken接口
  • 校验返回的appIntegrity、deviceIntegrity等字段,确认应用和设备合法性,以此替代reCAPTCHA验证

关键注意事项

  • 应用需上传至Google Play Console(至少内部测试版),本地调试需配置调试令牌
  • Nonce必须随机唯一,建议由后端生成后传递给前端
  • 所有验证逻辑必须在后端执行,禁止前端处理验证逻辑

内容的提问来源于stack exchange,提问作者Akshay Tripathi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 03:22:42