【问题标题】:Woocommerce rest api invalid signature (error 401) on post requestWoocommerce rest api 在发布请求时签名无效(错误 401)
【发布时间】:2017-07-16 09:39:54
【问题描述】:

我正在为 woocommerce 商店开发 Ionic 2 项目。我在我的应用程序中使用Woocommerce REST API,并使用Postman Chrome App 使用OAuth-1.0 测试API。我通过 GET 请求得到了正确的响应,但对于 POST 请求,我收到了签名不匹配的错误,如下所示:

{
  "code": "woocommerce_rest_authentication_error",
  "message": "Invalid Signature - provided signature does not match.",
  "data": {
    "status": 401
  }
}

【问题讨论】:

    标签: php wordpress postman woocommerce-rest-api oauth-1.0a


    【解决方案1】:

    我为此苦苦挣扎了几天(使用角度),最后发现这是一个 CORS 问题。浏览器实际上发送了一个 OPTIONS 请求,woocommerce-api 将其作为 GET 接收。使用 this tool 有助于排除故障。

    最后通过如下设置我的.htaccess来解决它;

    RewriteCond %{REQUEST_METHOD} OPTIONS
    RewriteRule ^(.*)$ $1 [R=200,L,E=HTTP_ORIGIN:%{HTTP:ORIGIN}]]
    Header set Access-Control-Allow-Origin "*"
    Header always set Access-Control-Allow-Credentials "true"
    Header always set Access-Control-Max-Age "1000"
    Header always set Access-Control-Allow-Headers "X-Requested-With, Content-Type, Origin, Authorization, Accept, Client-Security-Token, Accept-Encoding"
    Header always set Access-Control-Allow-Methods "POST, GET, OPTIONS, DELETE, PUT"
    

    详细解释可以参考this answer

    【讨论】:

    • 澄清(如果我错了请纠正我):RewriteCond 和RewriteRule 基本上为每个OPTIONS 请求返回一个HTTP 200。浏览器(至少在 HTTPS 环境中)在每个 GET/POST/etc 调用之前发出一个 OPTIONS 调用。如果返回200,则它有权进行实际调用。
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2013-01-16
    • 2019-02-05
    • 2021-03-31
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多