React-native-keychain: [Android] generated generic password contains invalid characters on Android X

Created on 1 Oct 2019  Â·  5Comments  Â·  Source: oblador/react-native-keychain

I've been using this module for a while and everything worked like a charm until I began experiencing weird authentication issues on devices with Android X.

What's happening:
I log into my app and everything is fine, but when I close it and open it again I'm getting lots of 401 requests.

Why I think that's happening
I checked the headers in my requests and found out that the access token I'm sending from devices with Android X looks like this:

Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImp0aSI6IjFiNjZiYTAwZDE0NWUwZDU4NDcyNDdmN2Y3NjI4MjdiOWQ0YmM1ZDk1MTk1Nzk3ZjJiZTkyZjZhZGViZmRlZmViNTE3YjI5YmUwNDE5YzgzIn0.eyJhdWQiOiIyIiwianRpIjoiMWI2NmJhMDBkMTQ1ZTBkNTg0NzI0N2Y3Zjc2MjgyN2I5ZDRiYzVkOTUxOTU3OTdmMmJlOTJmNmFkZWJmZGVmZWI1MTdiMjliZTA0MTljODMiLCJpYXQiOjE1Njk5MzY5MjIsIm5iZiI6MTU2OTkzNjkyMiwiZXhwIjoxNjAxNTU5MzIyLCJzdWIiOiIzOSIsInNjb3BlcyI6�V��$$E8�h���pZ�0aa7prVhfpK95X9QTVAEn8aMLsBoYyCRUJec75btRMUchWbfkllYCZz3vAgrEsXlvwjWAyV-nY_BEFGUtXfOexshy5jNBT049Z0i8i-qIiQmIfnP���J�  uJi��Рh�0uMRZNItw8sDCypfLjEHBxxS9d6VjA4u4M-eidXFfYsq6UQhNNos2tt4D-U1ctbbzQOTot0R97Tl6-u012vr-VIqOAlNZVjDj9LBm1Ug_RRHze9pUnKSeQBNMvZa_tTbD2ueAVQzIOT1G7DsIpLXIoRdIZpQVg7E2lcsCMZK_NlqY5jAFj9dIB_r1KOgnT3H0r12KCO278WQ2EalzrW5NB9MHASGP7o0btvxjQYPUh8X0qHuiKNgfkchHT8fQz-fdTtam9Y0-zK4WAinayXyRoPzgmS3MQdgc-vvBJ7_HflyiKRiRgNETHKHBPAV1KtRwLGmjB3jZSd5J-fMIoGkmUdT7HjI3sXemOez8pqCnX9Fhpi6zaAIV6IFALmP8tK__0aa7prVhfpK95X9QTVAEn8aMLsBoYyCRUJec75btRMUchWbfkllYCZz3vAgrEsXlvwjWAyV-nY_BEFGUtXfOexshy5jNBT049Z0i8i-qIiQmIfnPKxo2XGkfD4mUmT3zTIq2HwJJSy5n6LKcsVk2W_o2qp5jzphA

Notice the weird characters (�) present in that string which is what I get after running
getGenericPassword([{ authenticationPrompt, service }]) like in the docs.

This does not happen in devices with Android less than 10.

What I've tried so far
I tried setting the securityLevel to SECURE_SOFTWARE when I set the generic password to no avail

setGenericPassword(username, password, [{ securityLevel: Keychain.Keychain.SECURITY_LEVEL.SECURE_SOFTWARE }])

Is there something I'm missing to generate a generic password without those characters?
Any help would be much appreciated.

I'm leaving my versions here:

  • React Native: 0.60.6 (using jetifier)
  • Keychain: 4.0.1

Most helpful comment

We are having the same issues storing tokens on the Pixel devices. Any update on this ?
Are there any problems of avoiding Strongbox?

All 5 comments

Update: turns out this was related to #208 (I am also using a Pixel 3).

I tried this: https://github.com/Pilloxa/react-native-keychain/commit/70d79143161a00d7f3049eaef2b43cda3673f5e7 deactivating StrongBox and it indeed worked. I'm going to wait for a merge or an alternative release

We are having the same issues storing tokens on the Pixel devices. Any update on this ?
Are there any problems of avoiding Strongbox?

hello @samcampisi can you please share a runnable reproduction of the issue? That way we'll be able to take a look at it and fix it. see https://stackoverflow.com/help/minimal-reproducible-example. Thanks

I am still having this issue with v6.0.0

Was this page helpful?
0 / 5 - 0 ratings