You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MacOS下添加CFBundleURLTypes至授权文件致公证后签名无效错误

Electron Mac应用公证后添加CFBundleURLTypes崩溃问题解决

问题描述

我在Electron应用的授权文件中添加CFBundleURLTypes条目以实现深度链接功能,未公证时配置正常运行,但完成公证后,添加该条目会导致应用启动即崩溃,并触发「无效签名」错误,尽管公证流程并未提示失败。想确认是否需要额外配置(比如在配置描述文件中添加对应条目),目前未发现配置存在问题,调研显示该配置本应正常工作。

当前授权文件(entitlements.mac.plist)内容

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>com.apple.security.cs.allow-jit</key>
    <true/>
    <key>com.apple.security.cs.allow-dyld-environment-variables</key>
    <true/>
    <key>com.apple.security.cs.disable-library-validation</key>
    <true/>
    <key>com.apple.security.network.client</key>
    <true/>
    <key>com.apple.security.network.server</key>
    <true/>
    <key>com.apple.security.files.user-selected.read-write</key>
    <true/>
    <key>com.apple.security.cs.allow-unsigned-executable-memory</key>
    <true/>
    <key>com.apple.security.device.audio-input</key>
    <true/>
    <key>com.apple.security.device.camera</key>
    <true/>
  <key>CFBundleURLTypes</key>
  <array>
  <dict>
    <key>CFBundleTypeRole</key>
    <string>Editor</string>
    <key>CFBundleURLName</key>
    <string>my-protocol-name-here</string>
    <key>CFBundleURLSchemes</key>
    <array>
      <string>my-protocol-name-here</string>
    </array>
  </dict>
</array>
</dict>
</plist>

解决步骤

  • 迁移CFBundleURLTypes到Info.plist
    CFBundleURLTypes是应用的元数据配置,不属于授权文件的权限声明范畴,应该放在应用的Info.plist中。将授权文件里的CFBundleURLTypes节点完整移到Info.plist的<dict>根节点下,格式保持不变。

  • 清理授权文件
    从entitlements.mac.plist中删除CFBundleURLTypes相关的所有代码,确保授权文件只包含权限类的配置项。

  • 重新签名并执行公证
    使用修改后的授权文件重新对应用签名,然后再次提交公证。确保签名命令中指定了正确的授权文件路径,例如:

    codesign --deep --force --sign "Developer ID Application: Your Team Name" --entitlements entitlements.mac.plist YourApp.app
    
  • 验证签名与公证状态
    用以下命令检查签名有效性:

    codesign --verify --deep --strict --verbose=2 YourApp.app
    

    验证公证状态:

    spctl --assess --verbose=4 YourApp.app
    

    若输出中显示accepted和source=Notarized Developer ID,则说明签名和公证均正常。

  • 关于配置描述文件
    深度链接功能不需要在配置描述文件中额外添加条目,只要Info.plist配置正确,签名和公证流程正常即可生效。

内容的提问来源于stack exchange,提问作者shiva

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 02:50:27