Flutter使用Dio请求HTTP接口报错:Bad state: Insecure HTTP is not allowed by platform
Fixing "Insecure HTTP is not allowed by platform" Error in Flutter with Dio
Hey there, I’ve dealt with this exact error plenty of times—modern mobile platforms (Android and iOS) block unencrypted HTTP requests by default for security reasons. Let’s walk through how to fix this for both platforms, with options for testing and production-ready setups.
Android Solution
Option 1: Allow all HTTP traffic (for testing only!)
This is quick for local development, but never use this in production:
- Open your project’s
android/app/src/main/AndroidManifest.xmlfile - Add the
android:usesCleartextTraffic="true"attribute to the<application>tag:
<application android:name="io.flutter.app.FlutterApplication" android:label="YourAppName" android:icon="@mipmap/ic_launcher" android:usesCleartextTraffic="true"> <!-- Add this line --> <!-- Rest of your application content --> </application>
Option 2: Allow specific HTTP domains (production-ready)
For production, restrict access to only your private API domain:
- Create a new file at
android/app/src/main/res/xml/network_security_config.xml - Add this content, replacing
your-private-api-domain.comwith your actual API URL:
<?xml version="1.0" encoding="utf-8"?> <network-security-config> <domain-config cleartextTrafficPermitted="true"> <domain includeSubdomains="true">your-private-api-domain.com</domain> </domain-config> </network-security-config>
- Reference this config in your
AndroidManifest.xml’s<application>tag:
<application android:name="io.flutter.app.FlutterApplication" android:label="YourAppName" android:icon="@mipmap/ic_launcher" android:networkSecurityConfig="@xml/network_security_config"> <!-- Add this line --> <!-- Rest of your application content --> </application>
iOS Solution
Option 1: Allow all HTTP traffic (for testing only!)
Again, this is for development only—avoid in production:
- Open
ios/Runner/Info.plist - Add the
NSAppTransportSecuritydictionary withNSAllowsArbitraryLoadsset toYES:
<key>NSAppTransportSecurity</key> <dict> <key>NSAllowsArbitraryLoads</key> <true/> </dict>
Option 2: Allow specific HTTP domains (production-ready)
Lock down access to just your API domain:
- Open
ios/Runner/Info.plist - Add the
NSAppTransportSecuritydictionary with an exception for your domain:
<key>NSAppTransportSecurity</key> <dict> <key>NSExceptionDomains</key> <dict> <key>your-private-api-domain.com</key> <dict> <key>NSIncludesSubdomains</key> <true/> <key>NSTemporaryExceptionAllowsInsecureHTTPLoads</key> <true/> </dict> </dict> </dict>
Final Notes
- After making these changes, restart your Flutter app and rebuild the native project (sometimes a hot reload won’t pick up native config changes)
- Always use the domain-specific options for production—allowing all HTTP traffic exposes your users to security risks
- Dio itself doesn’t require any additional configuration here; the issue is entirely with the platform’s security policies
内容的提问来源于stack exchange,提问作者Ahmad Mohy
相关产品推荐
相关产品推荐

