You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flutter应用上架Google Play遇两类警告:明文流量与用户证书求助

Flutter 网络安全配置问题解决方案

问题1:限制用户证书仅在Debug模式生效

直接修改Android端网络安全配置,确保用户证书信任仅在调试场景启用:

  1. 打开Flutter项目的android/app/src/main/res/xml目录,创建或编辑network_security_config.xml,写入以下内容:
<?xml version="1.0" encoding="utf-8"?>
<network-security-config>
    <!-- Release模式仅信任系统证书 -->
    <base-config>
        <trust-anchors>
            <certificates src="system" />
        </trust-anchors>
    </base-config>

    <!-- Debug模式额外信任用户证书 -->
    <debug-overrides>
        <trust-anchors>
            <certificates src="system" />
            <certificates src="user" />
        </trust-anchors>
    </debug-overrides>
</network-security-config>
  1. 在android/app/src/main/AndroidManifest.xml的<application>标签中添加配置引用:
<application
    ...
    android:networkSecurityConfig="@xml/network_security_config">
    ...
</application>

配置完成后,仅当Flutter处于Debug模式(默认android:debuggable="true")时,应用才会信任用户安装的证书,Release模式下仅依赖系统证书,规避数据被窃听篡改的风险。

问题2:禁止全局明文流量

通过网络安全配置关闭全局明文流量,或仅对必要域名开放:

方案1:全局禁用明文流量

在network_security_config.xml的<base-config>中添加cleartextTrafficPermitted="false":

<?xml version="1.0" encoding="utf-8"?>
<network-security-config>
    <base-config cleartextTrafficPermitted="false">
        <trust-anchors>
            <certificates src="system" />
        </trust-anchors>
    </base-config>

    <!-- 保留Debug模式证书配置 -->
    <debug-overrides>
        <trust-anchors>
            <certificates src="system" />
            <certificates src="user" />
        </trust-anchors>
    </debug-overrides>
</network-security-config>

方案2:仅允许特定域名使用明文流量

若存在必须使用HTTP的旧域名,可单独配置:

<?xml version="1.0" encoding="utf-8"?>
<network-security-config>
    <base-config cleartextTrafficPermitted="false">
        <trust-anchors>
            <certificates src="system" />
        </trust-anchors>
    </base-config>

    <!-- 允许指定域名使用明文流量 -->
    <domain-config cleartextTrafficPermitted="true">
        <domain includeSubdomains="true">your-legacy-domain.com</domain>
    </domain-config>

    <debug-overrides>
        <trust-anchors>
            <certificates src="system" />
            <certificates src="user" />
        </trust-anchors>
    </debug-overrides>
</network-security-config>

同样需要在AndroidManifest.xml中引用该配置文件。

内容的提问来源于stack exchange,提问作者Mohd Shayan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 14:24:18