You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flutter使用Dio请求HTTP接口报错:Bad state: Insecure HTTP is not allowed by platform

Fixing "Insecure HTTP is not allowed by platform" Error in Flutter with Dio

Hey there, I’ve dealt with this exact error plenty of times—modern mobile platforms (Android and iOS) block unencrypted HTTP requests by default for security reasons. Let’s walk through how to fix this for both platforms, with options for testing and production-ready setups.

Android Solution

Option 1: Allow all HTTP traffic (for testing only!)

This is quick for local development, but never use this in production:

  1. Open your project’s android/app/src/main/AndroidManifest.xml file
  2. Add the android:usesCleartextTraffic="true" attribute to the <application> tag:
<application
    android:name="io.flutter.app.FlutterApplication"
    android:label="YourAppName"
    android:icon="@mipmap/ic_launcher"
    android:usesCleartextTraffic="true"> <!-- Add this line -->
    <!-- Rest of your application content -->
</application>

Option 2: Allow specific HTTP domains (production-ready)

For production, restrict access to only your private API domain:

  1. Create a new file at android/app/src/main/res/xml/network_security_config.xml
  2. Add this content, replacing your-private-api-domain.com with your actual API URL:
<?xml version="1.0" encoding="utf-8"?>
<network-security-config>
    <domain-config cleartextTrafficPermitted="true">
        <domain includeSubdomains="true">your-private-api-domain.com</domain>
    </domain-config>
</network-security-config>
  1. Reference this config in your AndroidManifest.xml’s <application> tag:
<application
    android:name="io.flutter.app.FlutterApplication"
    android:label="YourAppName"
    android:icon="@mipmap/ic_launcher"
    android:networkSecurityConfig="@xml/network_security_config"> <!-- Add this line -->
    <!-- Rest of your application content -->
</application>

iOS Solution

Option 1: Allow all HTTP traffic (for testing only!)

Again, this is for development only—avoid in production:

  1. Open ios/Runner/Info.plist
  2. Add the NSAppTransportSecurity dictionary with NSAllowsArbitraryLoads set to YES:
<key>NSAppTransportSecurity</key>
<dict>
    <key>NSAllowsArbitraryLoads</key>
    <true/>
</dict>

Option 2: Allow specific HTTP domains (production-ready)

Lock down access to just your API domain:

  1. Open ios/Runner/Info.plist
  2. Add the NSAppTransportSecurity dictionary with an exception for your domain:
<key>NSAppTransportSecurity</key>
<dict>
    <key>NSExceptionDomains</key>
    <dict>
        <key>your-private-api-domain.com</key>
        <dict>
            <key>NSIncludesSubdomains</key>
            <true/>
            <key>NSTemporaryExceptionAllowsInsecureHTTPLoads</key>
            <true/>
        </dict>
    </dict>
</dict>

Final Notes

  • After making these changes, restart your Flutter app and rebuild the native project (sometimes a hot reload won’t pick up native config changes)
  • Always use the domain-specific options for production—allowing all HTTP traffic exposes your users to security risks
  • Dio itself doesn’t require any additional configuration here; the issue is entirely with the platform’s security policies

内容的提问来源于stack exchange,提问作者Ahmad Mohy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 11:07:42