0Pricing
Kotlin Multiplatform Academy · 课时

安全地存储认证令牌

一种持久化凭据的实用模式

安全地存储认证令牌 是 CoddyKit 上的免费 Kotlin Multiplatform Academy 课时。 这是第 4 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Kotlin Multiplatform Academy 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Kotlin Multiplatform Academy 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Tokens Need a Home

After login, your app holds an auth token it must remember across restarts. Where you keep it matters a lot. 🔐

Plain Settings Isn't Secure

Regular Settings stores values in plain text. That's fine for a theme, but risky for a token that grants account access.

Encrypted Storage

For secrets, use platform-backed encrypted storage: the Keychain on iOS and EncryptedSharedPreferences on Android.

Hide It Behind an Interface

Define a small shared TokenStore interface so commonMain never knows which secure backend each platform uses.

interface TokenStore {
    fun save(token: String)
    fun read(): String?
    fun clear()
}

expect the Implementation

Declare the factory with expect in commonMain. Each platform supplies the secure actual version.

expect fun createTokenStore(): TokenStore

Save After Login

Right after a successful sign-in, write the token through your shared store. The UI never touches storage directly.

fun onLogin(store: TokenStore, token: String) {
    store.save(token)
}

Read on Startup

On launch, read the token to decide whether the user is already signed in or should see the login screen.

val loggedIn = store.read() != null

Attach to Requests

Feed the token into your Ktor client as a Bearer header so every authenticated call carries it automatically.

header("Authorization", "Bearer " + token)

Clear on Logout

When the user signs out, clear the token so it can never be reused. Always wipe credentials deliberately.

fun onLogout(store: TokenStore) {
    store.clear()
}

Never Log Tokens

Keep tokens out of logs and crash reports. A leaked secret in a log file is as dangerous as plain-text storage.

One Pattern, Both Apps

This expect/actual pattern keeps your shared code clean while each platform handles secrets the secure, native way.

Quick Check

Let's confirm the secure-storage approach.

Recap

You store tokens in secure platform storage behind a shared TokenStore, save after login, clear on logout, and never log secrets. That wraps the course! 🎉

常见问题解答

「安全地存储认证令牌」课时是免费的吗?

是的 — 「安全地存储认证令牌」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Kotlin Multiplatform Academy 课程的其余内容,请升级到 CoddyKit PRO。 Kotlin Multiplatform Academy 课程共包含 4 节课。

「安全地存储认证令牌」这节课中我会学到什么?

一种持久化凭据的实用模式 你通过在浏览器中直接运行的动手代码来练习 Kotlin Multiplatform Academy,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Kotlin Multiplatform Academy 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Kotlin Multiplatform Academy 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 4 节课,共 4 节。

「安全地存储认证令牌」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Kotlin Multiplatform Academy 课中编写并运行代码吗?

能。每节 Kotlin Multiplatform Academy 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 为什么需要设置抽象
  2. 读取和写入类型化值
  3. 默认值与清除键
  4. 安全地存储认证令牌
← 返回 Kotlin Multiplatform Academy