IBM Worklight - 如何在Worklight Console中启用应用程序真实性?

Pei*_*Soo 1 worklight-security ibm-mobilefirst

我尝试按照这个网址上的教程,教程是如此直接,但我无法得到正确的结果.

下面是我的authenticationConfig.xml

<securityTests>
  <customSecurityTest name="custom-mobilesecurityTest">
    <test realm="wl_antiXSRFRealm" step="1"/>
    <test realm="wl_authenticityRealm" step="2"/>
    <test realm="HeaderAuthRealm" isInternalUserID="true" step="3"/>
  </customSecurityTest>
</securityTests>
Run Code Online (Sandbox Code Playgroud)

但是控制台中出现的App Authentication始终是"Access Disabled",我无法启用它.我在这里错过了什么吗?

在此输入图像描述

Ida*_*dar 5

如果您提到您实际完成的内容会更有帮助,因为配置authenticationConfig.xml只是几个步骤中的一步.

另请注意,要使App Authenticity 真正起作用而不使用虚拟实现,您必须使用 IBM Worklight的Consumer版本(即,成为付费客户并安装正确版本的Worklight Studio和Worklight Server).


我相信,对于你的问题,你还没有完成下面的第2步.


启用应用程序真实性的步骤:

  1. 配置具有该wl_authenticityRealm领域的安全测试:

    <customSecurityTest name="customTests">
         <test realm="wl_antiXSRFRealm" step="1"/>
         <test realm="wl_authenticityRealm" step="1"/>
         <test realm="wl_remoteDisableRealm" step="1"/>
         <test realm="wl_anonymousUserRealm" isInternalUserID="true" step="1"/>
         <test realm="wl_deviceNoProvisioningRealm" isInternalDeviceID="true" step="2"/>
    </customSecurityTest>
    
    Run Code Online (Sandbox Code Playgroud)

    ^这在幻灯片9中提到

  2. 将其securityTest放在环境中application-descriptor.xml,例如:

    <android version="1.0" securityTest="customTests">
    
    Run Code Online (Sandbox Code Playgroud)
  3. 对于Android,生成公共签名密钥:

    <android version="1.0" securityTest="customTests">
            <worklightSettings include="true"/>
            <security>
                <encryptWebResources enabled="false"/>
                <testWebResourcesChecksum enabled="false" ignoreFileExtensions="png, jpg, jpeg, gif, mp4, mp3"/>
                <publicSigningKey>MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBdfdsfdsfiQKBgQCPCbaCfAfnAqQ12/S5LLfA4cBz/3INyLRPhFGSVFztdWNzPhrna1xDc8/3V1sUIW2odfdfddfdfffdR2n3dAnNMVydfdfdfv68gmU5qVCN4LxSKKRAj7VVbhBxBIEt5MbY+c0o7NZ2Pgu/moJee8Wgu8veZ1TJntYn+cWCYuI/JSnA9nsskwhSdPHK32edsfsdfdfQIDAQAB</publicSigningKey>
            </security>
        </android>
    
    Run Code Online (Sandbox Code Playgroud)

    ^幻灯片10-13中提到了这一点

  4. 对于iOS,请放置应用bundleId:

    <iphone bundleId="com.worklight.test" version="1.0" securityTest="customTests">

    ^幻灯片10-13中提到了这一点

  5. 在Worklight Development Server上运行方式>运行

现在,应在Worklight Console中为您启用App Authenticity下拉列表.