I've been using this module for a while and everything worked like a charm until I began experiencing weird authentication issues on devices with Android X.
What's happening:
I log into my app and everything is fine, but when I close it and open it again I'm getting lots of 401 requests.
Why I think that's happening
I checked the headers in my requests and found out that the access token I'm sending from devices with Android X looks like this:
Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImp0aSI6IjFiNjZiYTAwZDE0NWUwZDU4NDcyNDdmN2Y3NjI4MjdiOWQ0YmM1ZDk1MTk1Nzk3ZjJiZTkyZjZhZGViZmRlZmViNTE3YjI5YmUwNDE5YzgzIn0.eyJhdWQiOiIyIiwianRpIjoiMWI2NmJhMDBkMTQ1ZTBkNTg0NzI0N2Y3Zjc2MjgyN2I5ZDRiYzVkOTUxOTU3OTdmMmJlOTJmNmFkZWJmZGVmZWI1MTdiMjliZTA0MTljODMiLCJpYXQiOjE1Njk5MzY5MjIsIm5iZiI6MTU2OTkzNjkyMiwiZXhwIjoxNjAxNTU5MzIyLCJzdWIiOiIzOSIsInNjb3BlcyI6�V��$$E8�h���pZ�0aa7prVhfpK95X9QTVAEn8aMLsBoYyCRUJec75btRMUchWbfkllYCZz3vAgrEsXlvwjWAyV-nY_BEFGUtXfOexshy5jNBT049Z0i8i-qIiQmIfnP���J� uJi��Рh�0uMRZNItw8sDCypfLjEHBxxS9d6VjA4u4M-eidXFfYsq6UQhNNos2tt4D-U1ctbbzQOTot0R97Tl6-u012vr-VIqOAlNZVjDj9LBm1Ug_RRHze9pUnKSeQBNMvZa_tTbD2ueAVQzIOT1G7DsIpLXIoRdIZpQVg7E2lcsCMZK_NlqY5jAFj9dIB_r1KOgnT3H0r12KCO278WQ2EalzrW5NB9MHASGP7o0btvxjQYPUh8X0qHuiKNgfkchHT8fQz-fdTtam9Y0-zK4WAinayXyRoPzgmS3MQdgc-vvBJ7_HflyiKRiRgNETHKHBPAV1KtRwLGmjB3jZSd5J-fMIoGkmUdT7HjI3sXemOez8pqCnX9Fhpi6zaAIV6IFALmP8tK__0aa7prVhfpK95X9QTVAEn8aMLsBoYyCRUJec75btRMUchWbfkllYCZz3vAgrEsXlvwjWAyV-nY_BEFGUtXfOexshy5jNBT049Z0i8i-qIiQmIfnPKxo2XGkfD4mUmT3zTIq2HwJJSy5n6LKcsVk2W_o2qp5jzphA
Notice the weird characters (�) present in that string which is what I get after running
getGenericPassword([{ authenticationPrompt, service }]) like in the docs.
This does not happen in devices with Android less than 10.
What I've tried so far
I tried setting the securityLevel to SECURE_SOFTWARE when I set the generic password to no avail
setGenericPassword(username, password, [{ securityLevel: Keychain.Keychain.SECURITY_LEVEL.SECURE_SOFTWARE }])
Is there something I'm missing to generate a generic password without those characters?
Any help would be much appreciated.
I'm leaving my versions here:
Update: turns out this was related to #208 (I am also using a Pixel 3).
I tried this: https://github.com/Pilloxa/react-native-keychain/commit/70d79143161a00d7f3049eaef2b43cda3673f5e7 deactivating StrongBox and it indeed worked. I'm going to wait for a merge or an alternative release
We are having the same issues storing tokens on the Pixel devices. Any update on this ?
Are there any problems of avoiding Strongbox?
@RameshKothapalli https://github.com/oblador/react-native-keychain/issues/208#issuecomment-547480869
hello @samcampisi can you please share a runnable reproduction of the issue? That way we'll be able to take a look at it and fix it. see https://stackoverflow.com/help/minimal-reproducible-example. Thanks
I am still having this issue with v6.0.0
Most helpful comment
We are having the same issues storing tokens on the Pixel devices. Any update on this ?
Are there any problems of avoiding Strongbox?