You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Chrome 65无HTTPS环境下Google一键注册登录报错解决方案咨询

Fix for Google One Tap Sign-In Error on Chrome 65 (Non-HTTPS Environment)

Hey there, let's walk through how to resolve this Google One Tap sign-in/autologin issue you're seeing on Chrome 65. First, let's break down why this is happening:

The current environment does not provide window.crypto.subtle. This is required by the API to work. This is likely due to an old browser, or running the API in an unsecure origin - only secure origins (https: and localhost) provide crypto.subtle

Chrome 65 enforces the W3C security specification that restricts access to window.crypto.subtle to secure origins only (HTTPS or localhost). Firefox 59 hadn’t fully rolled out this restriction yet, which is why it works smoothly there.

Here are your actionable solutions, ordered by how strongly I recommend them:

1. Migrate to HTTPS (Best Long-Term Solution)

This is the most secure and sustainable fix. All modern browsers are tightening security to require HTTPS for sensitive APIs like crypto.subtle, and Google’s One Tap API is built with this security model in mind.

  • You can get free, trusted SSL certificates from services like Let's Encrypt—they’re straightforward to set up on most web servers.
  • HTTPS doesn’t just fix this One Tap issue; it also protects user data, boosts search engine rankings, and builds trust with your users.

2. Use localhost for Development Testing

If you’re working in a local dev environment, Chrome treats localhost as a secure origin by default. Deploy your test site to localhost (via tools like Apache, Nginx, or Node.js) and window.crypto.subtle will be available, letting One Tap function as expected.

3. Temporary Chrome Security Bypass (For Local Testing ONLY)

⚠️ Critical Warning: This is unsafe and should never be used in production or shared with users. This is only a quick workaround for local testing when you can’t switch to HTTPS or localhost immediately.

  • First, close all running Chrome windows completely.
  • Launch Chrome from the command line with these flags:
    chrome --unsafely-treat-insecure-origin-as-secure="http://your-insecure-domain.com" --user-data-dir="/tmp/chrome_dev_session"
    
    Replace http://your-insecure-domain.com with your actual non-HTTPS domain. The --user-data-dir flag creates a separate Chrome profile to avoid messing up your regular browser settings.

Final Note

Always prioritize HTTPS for any production environment. The temporary bypass is a last resort for local testing only—it exposes both you and your users to potential security risks if misused.

内容的提问来源于stack exchange,提问作者Hamed Moodi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 03:28:55