基于Dio包的Flutter应用如何禁用SSL Pinning以满足安全测试需求?
Got it, let's walk through this step by step since you're using Dio for your HTTP requests and need to turn off SSL pinning to let your security team run their tests.
First, a critical note: only use this setup in your testing environment—never ship this to production. Bypassing SSL certificate validation completely opens your app up to man-in-the-middle attacks, which is a huge security risk.
If you haven’t configured SSL pinning yet (just need to allow untrusted certificates)
Dio doesn’t enable SSL pinning by default, but if your testing environment uses self-signed certificates or you need to skip all certificate checks entirely, you can configure the HttpClientAdapter to ignore validation:
import 'package:dio/dio.dart'; import 'package:dio/io.dart'; import 'dart:io'; Dio getTestDioInstance() { final dio = Dio(); // Override the default HTTP client adapter to disable certificate checks dio.httpClientAdapter = IOHttpClientAdapter( createHttpClient: () { final httpClient = HttpClient(); // This callback tells the client to accept ANY certificate, even invalid ones httpClient.badCertificateCallback = (X509Certificate cert, String host, int port) => true; return httpClient; }, ); return dio; }
If you already have SSL pinning configured (need to remove it)
If you previously set up SSL pinning in your Dio instance (for example, using a PinningInterceptor or manually adding trusted certificates), you’ll need to:
- Remove any pinning-specific interceptors from your Dio instance
- Delete code that adds trusted certificates to the Dio client
- Replace the client adapter with the snippet above to ensure all certificate checks are skipped
Quick sanity check
After making these changes, test your HTTP requests with tools like Charles Proxy or Burp Suite. If you can intercept and inspect traffic without SSL errors, that confirms SSL pinning is disabled and your security team can proceed with their tests.
内容的提问来源于stack exchange,提问作者beratmirzaloglu

