安全地存储认证令牌
一种持久化凭据的实用模式
安全地存储认证令牌 是 CoddyKit 上的免费 Kotlin Multiplatform Academy 课时。 这是第 4 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Kotlin Multiplatform Academy 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Kotlin Multiplatform Academy 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Tokens Need a Home
After login, your app holds an auth token it must remember across restarts. Where you keep it matters a lot. 🔐
Plain Settings Isn't Secure
Regular Settings stores values in plain text. That's fine for a theme, but risky for a token that grants account access.
Encrypted Storage
For secrets, use platform-backed encrypted storage: the Keychain on iOS and EncryptedSharedPreferences on Android.
Hide It Behind an Interface
Define a small shared TokenStore interface so commonMain never knows which secure backend each platform uses.
interface TokenStore {
fun save(token: String)
fun read(): String?
fun clear()
}expect the Implementation
Declare the factory with expect in commonMain. Each platform supplies the secure actual version.
expect fun createTokenStore(): TokenStoreSave After Login
Right after a successful sign-in, write the token through your shared store. The UI never touches storage directly.
fun onLogin(store: TokenStore, token: String) {
store.save(token)
}Read on Startup
On launch, read the token to decide whether the user is already signed in or should see the login screen.
val loggedIn = store.read() != nullAttach to Requests
Feed the token into your Ktor client as a Bearer header so every authenticated call carries it automatically.
header("Authorization", "Bearer " + token)Clear on Logout
When the user signs out, clear the token so it can never be reused. Always wipe credentials deliberately.
fun onLogout(store: TokenStore) {
store.clear()
}Never Log Tokens
Keep tokens out of logs and crash reports. A leaked secret in a log file is as dangerous as plain-text storage.
One Pattern, Both Apps
This expect/actual pattern keeps your shared code clean while each platform handles secrets the secure, native way.
Quick Check
Let's confirm the secure-storage approach.
Recap
You store tokens in secure platform storage behind a shared TokenStore, save after login, clear on logout, and never log secrets. That wraps the course! 🎉
常见问题解答
「安全地存储认证令牌」课时是免费的吗?
是的 — 「安全地存储认证令牌」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Kotlin Multiplatform Academy 课程的其余内容,请升级到 CoddyKit PRO。 Kotlin Multiplatform Academy 课程共包含 4 节课。
「安全地存储认证令牌」这节课中我会学到什么?
一种持久化凭据的实用模式 你通过在浏览器中直接运行的动手代码来练习 Kotlin Multiplatform Academy,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Kotlin Multiplatform Academy 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Kotlin Multiplatform Academy 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 4 节课,共 4 节。
「安全地存储认证令牌」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Kotlin Multiplatform Academy 课中编写并运行代码吗?
能。每节 Kotlin Multiplatform Academy 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。