【问题标题】:HTTP 401 Basic Authentication error accessing Magento 2 Rest API访问 Magento 2 Rest API 的 HTTP 401 基本身份验证错误
【发布时间】:2018-10-31 13:41:35
【问题描述】:

我正在尝试在 Magento 2 中使用 Rest API。我有一段 PHP,它使用 cURL 首先为我的 Magento 用户获取管理令牌,然后使用该令牌返回一段 Magento 数据(在本例中产品类型列表)。第一部分返回没有问题的令牌,但第二部分返回 HTTP 401 基本身份验证错误。

我的代码是:

<?php

// Get handle for token retrieval
$userData = array("username" => "user", "password" => "password!");
$ch = curl_init("https://my.magento/rest/V1/integration/admin/token/");

// Set options
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($userData));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_HTTPHEADER, array("Content-Type: application/json", "Content-Length: " . strlen(json_encode($userData))));
curl_setopt($ch, CURLOPT_VERBOSE, true);
$verbose = fopen('/tmp/curl.log', 'w+');
curl_setopt($ch, CURLOPT_STDERR, $verbose);

// Get token
$token = curl_exec($ch);
echo "Token returned: " . $token . "<BR><BR>";

// Display log
rewind($verbose);
$verboseLog = stream_get_contents($verbose);
echo "Verbose information 1:\n<pre>", htmlspecialchars($verboseLog), "</pre>\n";

echo "About to get product<BR>";

// Get handle for product types
$ch = curl_init("https://my.magento/rest/V1/products/types/");

// Set options
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "GET");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_HTTPHEADER, array("Content-Type: application/json", "Authorization: Bearer " . json_decode($token)));
curl_setopt($ch, CURLOPT_VERBOSE, true);
$verbose = fopen('/tmp/curl.log', 'w+');
curl_setopt($ch, CURLOPT_STDERR, $verbose);

// Get types
$result = curl_exec($ch);
echo "Result: " . $result . "<BR>"; 

// Display log
rewind($verbose);
$verboseLog = stream_get_contents($verbose);
echo "<BR>Verbose information 2:\n<pre>", htmlspecialchars($verboseLog), "</pre>\n";

?>

浏览器输出是:

Tokenreturned: "t8iskt68xlo5frf9hhtc1lk8wmqzbzx8"

Verbose information 1: 
* About to connect() to my.magento port 443 (#2)
*   Trying 104.25.128.20...
* Connected to mymagento (nn.nn.nn.nn) port 443 (#2)
*   CAfile: /etc/pki/tls/certs/ca-bundle.crt
  CApath: none
* SSL connection using TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
* Server certificate:
*     subject: CN=ssl379212.cloudflaressl.com,OU=PositiveSSL Multi-Domain,OU=Domain Control Validated
*     start date: Oct 26 00:00:00 2018 GMT
*     expire date: May 04 23:59:59 2019 GMT
*     common name: ssl379212.cloudflaressl.com
*     issuer: CN=COMODO ECC Domain Validation Secure Server CA 2,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB
> POST /rest/V1/integration/admin/token/ HTTP/1.1
Host: sand2.firetoys.co.uk
Accept: */*
Content-Type: application/json
Content-Length: 48

* upload completely sent off: 48 out of 48 bytes
< HTTP/1.1 200 OK
< Date: Wed, 31 Oct 2018 12:50:01 GMT
< Content-Type: application/json; charset=utf-8
< Content-Length: 34
< Connection: keep-alive
< Set-Cookie: __cfduid=d69af7d1f0a1205231a8867c1f45875621540990201; expires=Thu, 31-Oct-19 12:50:01 GMT; path=/; domain=.my.magento; HttpOnly
< X-Frame-Options: SAMEORIGIN
< X-UA-Compatible: IE=edge
< Pragma: no-cache
< Expires: -1
< Cache-Control: no-store, no-cache, must-revalidate, max-age=0
< Accept-Ranges: bytes
< Set-Cookie: PHPSESSID=9p378rsfito8gfocnrufucssh6; expires=Wed, 31-Oct-2018 13:50:01 GMT; Max-Age=3600; path=/; domain=sand2.firetoys.co.uk; secure; HttpOnly
< Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
< Server: cloudflare
< CF-RAY: 47263eb629ea0ce9-LHR
< 
* Connection #2 to host my.magento left intact
About to get product
Result: 

Verbose information 2: 
* About to connect() to my.magento port 443 (#3)
*   Trying nn.nn.nn.nn...
* Connected to my.magento (nn.nn.nn.nn) port 443 (#3)
*   CAfile: /etc/pki/tls/certs/ca-bundle.crt
  CApath: none
* SSL connection using TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
* Server certificate:
*     subject: CN=ssl379212.cloudflaressl.com,OU=PositiveSSL Multi-Domain,OU=Domain Control Validated
*     start date: Oct 26 00:00:00 2018 GMT
*     expire date: May 04 23:59:59 2019 GMT
*     common name: ssl379212.cloudflaressl.com
*     issuer: CN=COMODO ECC Domain Validation Secure Server CA 2,O=COMODO CA Limited,L=Salford,ST=Greater Manchester,C=GB
> GET /rest/V1/products/types/ HTTP/1.1
Host: sand2.firetoys.co.uk
Accept: */*
Content-Type: application/json
Authorization: Bearer t8iskt68xlo5frf9hhtc1lk8wmqzbzx8

< HTTP/1.1 401 Unauthorized
< Date: Wed, 31 Oct 2018 12:50:01 GMT
< Content-Length: 0
< Connection: keep-alive
< Set-Cookie: __cfduid=d38c9e4bc3019d9ac55c7f68f5c5ca1161540990201; expires=Thu, 31-Oct-19 12:50:01 GMT; path=/; domain=.my.magento; HttpOnly
< X-Varnish: 7995397
< WWW-Authenticate: Basic
< Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
< Server: cloudflare
< CF-RAY: 47263eb70f5b3512-LHR
< 
* Connection #3 to host my.magento left intact

当我尝试直接浏览到 https://my.magento/rest/V1/products/types/ 时,我收到一个 Magento 错误,说我没有获得 Products 资源的授权,我希望这是因为我没有发送任何令牌或登录凭据,但至少它可以通过到 Magento。

有什么想法吗??

我应该补充一点,服务器设置为基本身份验证,如果我将承载身份验证替换为 GET 标头中必要的基本身份验证,它会返回有关无法访问资源的 Magento 消息,这是公平的足够。所以我猜有两个问题:

  1. 如果您不能将两个身份验证放入标头中,我如何才能通过基本身份验证并仍然在我的 GET 请求中包含不记名身份验证?

  2. 为什么在没有任何基本身份验证的情况下获取令牌的初始 POST 工作?

【问题讨论】:

    标签: rest magento http-status-code-401


    【解决方案1】:

    “鉴于您不能将两个身份验证放入标头中,我如何才能通过基本身份验证并仍然在我的 GET 请求中包含不记名身份验证?”

    禁用 /index.php/rest 位置的身份验证(在网络服务器中)

    “为什么在没有任何基本身份验证的情况下获取令牌的初始 POST 工作?”

    如果 POST 位置受到保护,那么您应该会收到 401 响应。 您是否在发布请求时将用户名和密码放在 url 上? http://user:pass@my.magento/rest/V1/

    顺便说一下,把 user:pass@my.magento 放到 URL 里,会被翻译成 Authorization: User 。

    但您还设置了 Authorization: Bearer t8iskt68xlo5frf9hhtc1lk8wmqzbzx8 ,这将覆盖 http authentification Authorization。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2012-02-13
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2016-02-04
      • 2019-02-26
      相关资源
      最近更新 更多