三星Galaxy S8设备上Android应用出现SecurityException崩溃求助
First, let's zero in on the core crash you're seeing from Crashlytics:
Fatal Exception: java.lang.RuntimeException: Unable to start activity ComponentInfo{com.bundle.id/com.bundle.id.MainActivity}: java.lang.SecurityException: uid 10346 cannot get secrets for accounts of type: com.osp.app.signin at android.app.ActivityThread.performLaunchActivity(ActivityThread.java:2955) at android.app.ActivityThread.handleLaunchActivity(ActivityThread.java:3030) at android.app.Activi...
This error boils down to a permission gap: your app (running under UID 10346) doesn’t have the necessary rights to access sensitive credentials (secrets) for accounts of type com.osp.app.signin. Let’s walk through fixes step by step:
1. Validate Manifest Permissions
Start by checking if you’ve declared the right permissions in your AndroidManifest.xml. For accessing account secrets, you’ll need at minimum:
android.permission.GET_ACCOUNTS(to access the list of accounts on the device)- A custom permission specific to
com.osp.app.signin(if the account provider requires it—often the case for OEM-specific services like OPPO’s OSP platform)
Add these inside your <manifest> tag:
<uses-permission android:name="android.permission.GET_ACCOUNTS" /> <!-- Example of a possible OEM-specific permission; confirm exact name from provider docs --> <uses-permission android:name="com.osp.app.signin.permission.ACCESS_ACCOUNT_SECRETS" />
2. Handle Runtime Permissions (Android 6.0+)
If your app targets API 23 or higher, GET_ACCOUNTS is a "dangerous" permission that needs to be requested at runtime. Make sure you’re checking and requesting this before trying to access account secrets:
private val REQUEST_ACCOUNT_PERMISSION = 1001 fun checkAndRequestAccountAccess() { if (ContextCompat.checkSelfPermission(this, Manifest.permission.GET_ACCOUNTS) != PackageManager.PERMISSION_GRANTED) { ActivityCompat.requestPermissions(this, arrayOf(Manifest.permission.GET_ACCOUNTS), REQUEST_ACCOUNT_PERMISSION) } else { // Proceed with fetching account secrets retrieveAccountSecrets() } } override fun onRequestPermissionsResult(requestCode: Int, permissions: Array<out String>, grantResults: IntArray) { super.onRequestPermissionsResult(requestCode, permissions, grantResults) if (requestCode == REQUEST_ACCOUNT_PERMISSION) { if (grantResults.isNotEmpty() && grantResults[0] == PackageManager.PERMISSION_GRANTED) { retrieveAccountSecrets() } else { // Let the user know the feature needs permission, or disable related functionality Toast.makeText(this, "Account access is required for this feature", Toast.LENGTH_SHORT).show() } } }
3. Check OEM-Specific Restrictions
The com.osp.app.signin account type is almost certainly tied to an OEM service (likely OPPO’s OSP platform). These services often have extra hoops:
- Your app may need to be signed with a certificate approved by the OEM to access account secrets.
- You might have to use the OEM’s official SDK (like OPPO Account SDK) instead of directly using Android’s
AccountManagerto pull secrets.
Check the OEM’s developer docs for exact integration rules—this is often the missing piece for these niche account types.
4. Add Graceful Exception Handling
If you can’t resolve the permission issue for all users (e.g., some devices have strict OEM locks), wrap your account secret logic in a try-catch to avoid fatal crashes:
fun retrieveAccountSecrets() { try { val accountManager = AccountManager.get(this) val ospAccounts = accountManager.getAccountsByType("com.osp.app.signin") if (ospAccounts.isNotEmpty()) { val secret = accountManager.getPassword(ospAccounts[0]) // Use the secret as needed } } catch (e: SecurityException) { // Log the error and handle gracefully Log.e("MainActivity", "Failed to access OSP account secrets", e) Toast.makeText(this, "Could not access account information", Toast.LENGTH_SHORT).show() // Fallback: disable features that rely on this secret, or navigate to a backup screen } }
By working through these steps, you’ll either fix the permission issue or prevent crashes for affected users.
内容的提问来源于stack exchange,提问作者Reshad

