【问题标题】:Unable to use oAuth Authentication on WooCommerce API over SSL无法通过 SSL 在 WooCommerce API 上使用 oAuth 身份验证
【发布时间】:2016-04-30 06:44:54
【问题描述】:

我正在尝试使用 oAuth 访问 WooCommerce REST API 的 V3 版本,以通过 SSL 进行身份验证。

我正在调用的运行 WooCommerce 的 Wordpress 实例是使用 AWS Elastic Beanstalk 托管的。

尝试使用 oAuth 时,我收到 401 响应。 发出请求的 URL 是 https://www.example.com/wc-api/v3/products?oauth_consumer_key=[my_key]&oauth_nonce=[nonce]&oauth_signature=[signature]%3D&oauth_signature_method=HMAC-SHA1&oauth_timestamp=1453572852&oauth_token=&oauth_version=1.0&filter%5Blimit%5D=500

作为我得到的响应的一部分

[WWW-Authenticate] => Array
    (
        [0] => Basic realm="WooCommerce API. Use a consumer key in the username field and a consumer secret in the password field"
    )

我知道我正在使用的消费者密钥和秘密很好,因为我已经能够在对同一站点的基本身份验证请求中成功使用它们。

我已经在我的开发环境(不在 AWS 上)中针对非 SSL 地址测试了相同的 oAuth 代码,效果很好。

我知道 WooCommerce 说您必须对 http 地址上的请求使用 oAuth - 但与您不能对 https 上的请求使用 oAuth 的情况相反吗?还是我需要配置服务器端的东西,这可能在我的开发环境和 AWS 上的生产环境之间有所不同?

【问题讨论】:

    标签: php wordpress oauth woocommerce


    【解决方案1】:

    如果您查看woocommerce/includes/api/class-wc-api-authentication.php,authenticate 函数会说:

    if ( is_ssl() ) {
        $keys = $this->perform_ssl_authentication();
    } else {
        $keys = $this->perform_oauth_authentication();
    }
    

    这意味着您不能将 oAuth 用于 https。 (根据 woocommerce 的说法,您不需要。)

    SSL 加密的请求不会受到嗅探或 中间人攻击,因此请求可以通过以下方式进行身份验证 只需查找与给定使用者密钥关联的用户,然后 确认提供的消费者秘密是有效的

    【讨论】:

      猜你喜欢
      • 2017-10-12
      • 2012-11-08
      • 2016-09-07
      • 2014-10-27
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2015-09-14
      • 1970-01-01
      相关资源
      最近更新 更多