Android FIDO注册报错SECURITY_ERR:请求无法验证排查求助
FIDO注册报错SECURITY_ERR:请求无法验证的排查问题
我正在开发一款演示型Android应用(基于Flutter,核心FIDO交互用原生Java代码),目标是展示FIDO登录功能。在FIDO注册流程中,系统返回错误:SECURITY_ERR The incoming request cannot be validated。
本地已完成全链路测试,通过/etc/hosts将域名squarephone.biz指向10.0.2.2,应用能正常连接本地FIDO服务器,但未观测到服务器收到assetlinks.json的请求,推测问题根源在此。
当前怀疑方向:
- 本地环境是否无法测试FIDO服务(但hosts配置应该能规避域名限制)
- 配置文件存在错误
另外,无法获取Android系统诊断日志,急需明确系统执行流程和失败原因。
核心代码与配置文件
核心注册代码(Kotlin)
private fun initiateRegistration( result: Result, challenge: String, userId: String, username: String, rpDomain: String, rpName: String, coseAlgoValue: List<Int>, excludeCredentials: List<String> ) { val rpEntity = PublicKeyCredentialRpEntity(rpDomain, rpName, null) val options = PublicKeyCredentialCreationOptions.Builder() .setRp(rpEntity) .setUser( PublicKeyCredentialUserEntity( userId.to(), userId, null, username ) ) .setChallenge(challenge.decodeBase64()) .setParameters( coseAlgoValue.map { PublicKeyCredentialParameters( PublicKeyCredentialType.PUBLIC_KEY.toString(), it ) } ) .setExcludeList( excludeCredentials.map { PublicKeyCredentialDescriptor( PublicKeyCredentialType.PUBLIC_KEY.toString(), it.decodeBase64(), null ) } ) .setAuthenticatorSelection( AuthenticatorSelectionCriteria.Builder().setAttachment(Attachment.PLATFORM).build() ) .build() val fidoClient = Fido.getFido2ApiClient(activity) val registerIntent = fidoClient.getRegisterPendingIntent(options) registerIntent.addOnFailureListener { val errCode = "FAILED_TO_GET_REGISTER_INTENT" result.error(errCode, it.message, null); } registerIntent.addOnSuccessListener { pendingIntent -> if (pendingIntent != null) { // Start a FIDO2 registration request. activity?.startIntentSenderForResult( pendingIntent.intentSender, REGISTER_REQUEST_CODE, null, 0, 0, 0 ) } else { val errCode = "FAILED_TO_GET_REGISTER_INTENT" result.error(errCode, "An error occurred", null); } } }
AndroidManifest.xml
<manifest xmlns:android="http://schemas.android.com/apk/res/android" package="dev.onepub.fido.client"> <application android:label="fido_client" android:name="${applicationName}" android:icon="@mipmap/ic_launcher"> <activity android:name=".MainActivity" android:exported="true" android:launchMode="singleTop" android:theme="@style/LaunchTheme" android:configChanges="orientation|keyboardHidden|keyboard|screenSize|smallestScreenSize|locale|layoutDirection|fontScale|screenLayout|density|uiMode" android:hardwareAccelerated="true" android:windowSoftInputMode="adjustResize"> <!-- Specifies an Android theme to apply to this Activity as soon as the Android process has started. This theme is visible to the user while the Flutter UI initializes. After that, this theme continues to determine the Window background behind the Flutter UI. --> <meta-data android:name="io.flutter.embedding.android.NormalTheme" android:resource="@style/NormalTheme" /> <intent-filter> <action android:name="android.intent.action.MAIN"/> <category android:name="android.intent.category.LAUNCHER"/> </intent-filter> </activity> <!-- Don't delete the meta-data below. This is used by the Flutter tool to generate GeneratedPluginRegistrant.java --> <meta-data android:name="flutterEmbedding" android:value="2" /> <!-- required by FIDO links to res/values/strings.xml--> <meta-data android:name="asset_statements" android:resource="@string/asset_statements" /> </application> </manifest>
strings.xml
<resources> <string name="asset_statements" translatable="false"> [{ "include": "http://squarephone.biz:8080/.well-known/assetlinks.json" }] </string> </resources>
assetlinks.json
[ { "relation" : [ "delegate_permission/common.handle_all_urls", "delegate_permission/common.get_login_creds" ], "target" : { "namespace" : "web", "site" : "http://squarephone.biz:8080" } }, { "relation" : [ "delegate_permission/common.handle_all_urls", "delegate_permission/common.get_login_creds" ], "target" : { "namespace" : "android_app", "package_name" : "dev.onepub.fido.client", "sha256_cert_fingerprints" : [ "XXXX:XXXX" ] } } ]
排查与解决方案
1. assetlinks.json 请求未触发的核心原因
Android系统对assetlinks.json的验证有严格要求,未触发请求大概率是以下问题:
- HTTP协议限制:Android 11+默认要求
assetlinks.json通过HTTPS获取,即使配置了hosts指向本地HTTP服务器,系统也会拒绝发起请求。本地测试需改用HTTPS,或在AndroidManifest的<application>标签中添加android:usesCleartextTraffic="true"(仅测试用,上线必须HTTPS)。 - asset_statements格式问题:strings.xml中的JSON必须是压缩无换行的格式,当前的换行和空格会导致解析失败,系统无法识别要请求的URL。修改为:
<string name="asset_statements" translatable="false">[{"include": "http://squarephone.biz:8080/.well-known/assetlinks.json"}]</string> - 域名匹配问题:
rpDomain必须与assetlinks.json中site的域名完全一致(不能带端口),如果注册时rpDomain传的是squarephone.biz:8080,系统会认为域名不匹配,跳过验证请求。
2. SECURITY_ERR 验证失败的排查点
- SHA256指纹错误:
assetlinks.json中的sha256_cert_fingerprints必须是当前调试/发布包的真实指纹,用以下命令获取调试包指纹:
注意指纹格式要全大写,冒号分隔,不能有多余空格。keytool -list -v -keystore ~/.android/debug.keystore -alias androiddebugkey -storepass android -keypass android - AuthenticatorSelection配置:
setAttachment(Attachment.PLATFORM)指定使用系统内置验证器(如指纹),部分模拟器或设备可能不支持,可先改为Attachment.CROSS_PLATFORM测试,排除设备兼容性问题。 - FIDO服务器配置:检查服务器返回的
challenge是否符合Base64 URL安全编码规范,coseAlgoValue是否为支持的算法(如-7对应ES256,-257对应RS256)。
3. 获取系统诊断日志的方法
即使无法直接查看系统日志,可通过以下方式获取FIDO相关日志:
- 使用adb命令过滤FIDO2相关日志:
adb logcat -s Fido2ApiClient Fido2Service - 在应用中添加
Fido.getFido2ApiClient(activity).enableDebugLogging(true),开启客户端调试日志。
内容的提问来源于stack exchange,提问作者Brett Sutton
相关产品推荐
相关产品推荐

