macOS自动评估配置中Electron应用频繁请求登录钥匙串的解决方法
问题背景
准备发布一款需在Automatic Assessment Configuration(自动评估配置)环境下运行的Electron/macOS桌面应用,已完成签名与公证,能在Apple-arm64设备启动评估模式,但每次启动都会弹出请求“login”钥匙串访问权限的系统对话框,全新用户账户也会出现该问题,说明与本地钥匙串存储内容无关。问题自添加配置描述文件测试评估功能后出现。
当前配置:
- entitlements.inherit.plist:
<key>com.apple.security.cs.allow-jit</key> <true/> <key>com.apple.security.cs.allow-unsigned-executable-memory</key> <true/>
- entitlements.plist:
<key>com.apple.security.cs.allow-jit</key> <true/> <key>com.apple.security.cs.allow-unsigned-executable-memory</key> <true/> <key>com.apple.developer.automatic-assessment-configuration</key> <true/>
- Electron builder配置片段:
mac: { notarize: false, target: 'dir', entitlements: 'buildResources/entitlements.mac.plist', provisioningProfile: 'buildResources/xyu.provisionprofile', entitlementsInherit: 'buildResources/entitlements.mac.inherit.plist', }
可能的解决方向
- 添加钥匙串访问权限声明
在entitlements.plist中明确指定钥匙串访问组,避免系统弹出宽泛的权限请求:
<key>com.apple.security.keychain-access-groups</key> <array> <string>$(AppIdentifierPrefix)com.yourcompany.yourapp</string> </array>
确保这里的组ID和配置描述文件中授权的钥匙串访问组完全一致。
调整代码签名权限组合
尝试移除com.apple.security.cs.allow-unsigned-executable-memory权限,部分场景下该权限与自动评估配置组合会触发系统额外的安全检查。如果应用确实需要该权限,再重新添加并测试。检查配置描述文件权限
确认你的provisioning profile中包含了com.apple.developer.automatic-assessment-configuration权限,同时没有多余的钥匙串相关权限配置冲突。可以在Apple开发者后台重新生成配置文件,确保权限与本地entitlements配置完全匹配。升级Electron版本
某些旧版Electron在自动评估配置模式下存在兼容性问题,尝试升级到最新稳定版,排查是否是底层组件触发的钥匙串访问请求。验证签名权限是否生效
通过终端命令重新验证应用的签名权限是否正确应用:
codesign -d --entitlements - /path/to/your/app
检查输出的权限列表是否和你配置的entitlements一致,避免签名过程中出现权限遗漏。
内容的提问来源于stack exchange,提问作者DreTaX

