【问题标题】:Using Nonce with Ajax in WordPress Plugin在 WordPress 插件中使用 Nonce 和 Ajax
【发布时间】:2011-12-04 20:04:03
【问题描述】:

我正在尝试在 WordPress 插件中使用随机数。我有一个表格,我想在上面使用随机数。

在php中:

function csf_enqueue() {

//I have other scripts enqueued in htis function 
wp_enqueue_script('my-ajax-handle', plugin_dir_url(__FILE__).'file-path', array('jquery', 'jquery-ui-core', 'jquery-ui-datepicker', 'google-maps'));

$data = array(
    'ajax_url' => admin_url( 'admin-ajax.php' ),
    'my_nonce' => wp_create_nonce('myajax-nonce')
);

wp_localize_script('my-ajax-handle', 'the_ajax_script', $data );

}

add_action('wp_enqueue_scripts', 'csf_enqueue');
add_action('wp_ajax_the_ajax_hook', 'the_action_function');
add_action('wp_ajax_nopriv_the_ajax_hook', 'the_action_function');

在 jQuery 文件中:

jQuery.post(the_ajax_script.ajaxurl, {my_nonce : the_ajax_script.my_nonce}, jQuery("#theForm").serialize() + "&maxLat="+ csf_dcscore_crime_map_bounds[0] + "&maxLong="+ csf_dcscore_crime_map_bounds[1] + "&minLat="+ csf_dcscore_crime_map_bounds[2] + "&minLong="+ csf_dcscore_crime_map_bounds[3],
                    function(response_from_the_action_function){
                        jQuery("#response_area").html(response_from_the_action_function);
                    });

我是否在 jQuery 中正确发布随机数?

在php中:

function the_action_function() {
   if( ! wp_verfiy_nonce( $nonce, 'myajax-nonce')) die ('Busted!');
//function continues

有什么建议吗?如果我去掉所有关于 nonce 的代码,一切正常。关于为什么它不起作用的任何想法?或者我该如何调试它?谢谢!

谢谢。

【问题讨论】:

    标签: wordpress jquery nonce


    【解决方案1】:

    有两件事不对。

    通过 jQuery post 方法发送数据,你不能像你做的那样发送一个对象+一个查询字符串。相反,您需要发送查询字符串格式或对象格式数据。为了方便您的情况,我将使用查询字符串格式。所以邮政编码应该是这样的

    jQuery.post( the_ajax_script.ajaxurl, 
                 jQuery("#theForm").serialize() + 
                        "&maxLat="+ csf_dcscore_crime_map_bounds[0] + 
                        "&maxLong="+ csf_dcscore_crime_map_bounds[1] + 
                        "&minLat="+ csf_dcscore_crime_map_bounds[2] + 
                        "&minLong="+ csf_dcscore_crime_map_bounds[3] +
                        "&my_nonce="+ the_ajax_script.my_nonce,
                 function(response_from_the_action_function) {
                     jQuery("#response_area")
                         .html(response_from_the_action_function);
                 });
    

    这将发送参数 my_nonce 中的随机数。现在可以替换服务器端了

    if( ! wp_verify_nonce( $nonce, 'myajax-nonce')) die ('Busted!');
    

    与

    if( ! wp_verify_nonce( $_POST['my_nonce'],'myajax-nonce')) die ('Busted!');
    

    查看jQuery.post 和wp_verfiy_nonce 的文档会对您有所帮助:)

    【讨论】:

    • 嗨,sbrajesh,非常感谢您的帮助。我对您建议的代码进行了更改。我还删除了“ajaxurl”中的下划线。不幸的是,我收到“致命错误:调用未定义函数 wp_verfiy_nonce()”。听起来该功能由于某种原因没有及时加载。有任何想法吗?谢谢!
    • 我在 wp_verify_nonce 中也有拼写错误。打字不好。谢谢!
    • 你确定它工作正常吗?如果它没有改变 `$data = array('ajax_url' => admin_url('admin-ajax.php'), 'my_nonce' => wp_create_nonce('myajax-nonce'));` 到 `$data = array( 'ajaxurl' => admin_url('admin-ajax.php'), 'my_nonce' => wp_create_nonce('myajax-nonce') ); ` 或将我的代码中的ajaxurl 替换为ajax_url,就像您在数据中一样
    猜你喜欢
    • 2013-07-25
    • 2018-03-15
    • 1970-01-01
    • 2014-11-09
    • 1970-01-01
    • 2022-01-11
    • 2015-07-01
    • 2017-12-25
    • 1970-01-01
    相关资源
    最近更新 更多