تخزين Auth Token بأمان
نمط عملي لحفظ بيانات الاعتماد
تخزين Auth Token بأمان درس مجاني في Kotlin Multiplatform Academy على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Kotlin Multiplatform Academy، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Kotlin Multiplatform Academy 4 دروس في المجموع.
بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.
Tokens Need a Home
After login, your app holds an auth token it must remember across restarts. Where you keep it matters a lot. 🔐
Plain Settings Isn't Secure
Regular Settings stores values in plain text. That's fine for a theme, but risky for a token that grants account access.
Encrypted Storage
For secrets, use platform-backed encrypted storage: the Keychain on iOS and EncryptedSharedPreferences on Android.
Hide It Behind an Interface
Define a small shared TokenStore interface so commonMain never knows which secure backend each platform uses.
interface TokenStore {
fun save(token: String)
fun read(): String?
fun clear()
}expect the Implementation
Declare the factory with expect in commonMain. Each platform supplies the secure actual version.
expect fun createTokenStore(): TokenStoreSave After Login
Right after a successful sign-in, write the token through your shared store. The UI never touches storage directly.
fun onLogin(store: TokenStore, token: String) {
store.save(token)
}Read on Startup
On launch, read the token to decide whether the user is already signed in or should see the login screen.
val loggedIn = store.read() != nullAttach to Requests
Feed the token into your Ktor client as a Bearer header so every authenticated call carries it automatically.
header("Authorization", "Bearer " + token)Clear on Logout
When the user signs out, clear the token so it can never be reused. Always wipe credentials deliberately.
fun onLogout(store: TokenStore) {
store.clear()
}Never Log Tokens
Keep tokens out of logs and crash reports. A leaked secret in a log file is as dangerous as plain-text storage.
One Pattern, Both Apps
This expect/actual pattern keeps your shared code clean while each platform handles secrets the secure, native way.
Quick Check
Let's confirm the secure-storage approach.
Recap
You store tokens in secure platform storage behind a shared TokenStore, save after login, clear on logout, and never log secrets. That wraps the course! 🎉
الأسئلة الشائعة
هل درس «تخزين Auth Token بأمان» مجاني؟
نعم — نص درس «تخزين Auth Token بأمان» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Kotlin Multiplatform Academy، انتقل إلى CoddyKit PRO. تتضمن دورة Kotlin Multiplatform Academy 4 دروس في المجموع.
ماذا ستتعلم في «تخزين Auth Token بأمان»؟
نمط عملي لحفظ بيانات الاعتماد تتمرن على Kotlin Multiplatform Academy مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.
هل أحتاج إلى خبرة سابقة لأبدأ Kotlin Multiplatform Academy؟
لا تُشترط خبرة سابقة. Kotlin Multiplatform Academy على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.
كم من الوقت يستغرق درس «تخزين Auth Token بأمان»؟
معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.
هل يمكنني كتابة وتشغيل أكواد في درس Kotlin Multiplatform Academy هذا؟
نعم. كل درس في Kotlin Multiplatform Academy يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.
جميع الدروس في هذه الدورة
- لماذا نحتاج إلى تجريد الإعدادات
- قراءة القيم ذات الأنواع وكتابتها
- القيم الافتراضية ومسح المفاتيح
- تخزين Auth Token بأمان