Ionic3指纹/面容ID登录及服务端存储可行性技术问询
Hey there! Let's break down your questions clearly—biometric auth is a great way to boost app security and user experience, so these are really solid asks.
1. Does Ionic 3 support Fingerprint/Face ID login?
Absolutely! You can implement this using a Cordova plugin that connects your Ionic app to the native biometric APIs of iOS and Android. The most reliable and widely used option is cordova-plugin-fingerprint-aio (Fingerprint All-In-One). It supports:
- iOS: Both Touch ID (for older devices) and Face ID (for modern iPhones/iPads)
- Android: Fingerprint authentication (compatible with most post-Android 6.0 devices)
Quick integration snippet:
First install the plugin via CLI:
ionic cordova plugin add cordova-plugin-fingerprint-aio npm install @ionic-native/fingerprint-aio
Then import it into your login page/service, and call its show() method to trigger the native biometric prompt. The plugin handles all local verification against the device's stored biometrics—you don't have to deal with low-level OS details.
2. Can we store Fingerprint/Face ID information on the server?
Short answer: No, you should never store raw biometric data (fingerprint scans, Face ID templates) on a server. Here's why:
- Privacy regulations (like GDPR, CCPA) classify biometric data as highly sensitive personal information, with strict rules around storage and handling.
- Native mobile OSes (iOS and Android) intentionally don't expose raw biometric data to apps. They only let you confirm if the user's biometrics match what's stored locally on the device—you never get access to the actual scan or template.
Instead, store a secure, non-biometric credential linked to the user's biometric verification. For example:
- After a user first logs in with a password, generate a unique encrypted auth token (like a JWT) on the server, send it to the app, and store it locally (use secure storage like
cordova-plugin-secure-storageinstead of plainlocalStorage). - When the user uses biometrics to log in, the plugin confirms their identity locally, then your app sends this pre-generated token to the server for validation.
3. Implementing your specific requirement (Biometric login with server matching)
Here's a step-by-step workflow to make this work seamlessly:
- Initial setup (first password login):
- User logs in with their username/password.
- Server generates a short-lived auth token and a longer-lived refresh token, then sends both to the app.
- App stores these tokens securely on the device.
- Biometric login flow:
- On the login page, add a "Login with Fingerprint/Face ID" button.
- When tapped, call the fingerprint plugin's
show()method to trigger the native biometric prompt. - If verification succeeds locally, retrieve the stored auth token from the device and send it to the server.
- Server checks if the token is valid (not expired, linked to an active user account) and grants access if everything matches.
Key security reminders:
- Always use HTTPS for all server communication to prevent token interception.
- Set expiration dates on your auth tokens and implement a refresh token flow to avoid forcing users to re-enter their password constantly.
- Add a fallback option (like password login) for cases where biometric verification fails (e.g., user's fingerprint changes, device doesn't support biometrics).
- For iOS, add the
NSFaceIDUsageDescriptionkey to yourInfo.plistto explain why your app needs Face ID access—Apple requires this for app store approval.
内容的提问来源于stack exchange,提问作者Wasim

