【问题标题】:Can't authenticate with basic authentication using WP REST API 2.0 plugin无法使用 WP REST API 2.0 插件通过基本身份验证进行身份验证
【发布时间】:2016-04-07 08:43:36
【问题描述】:

我遇到了基本身份验证问题。

尝试使用以下网址通过 Postman(chrome 插件)发送 GET 请求: http://_MY_WEBSITE_URL_/wp-json/wp/v2/users/3

用户名和密码字段填写了站点的管理员用户凭据。

我得到的错误:

{
    "code": "rest_user_cannot_view",
    "message": "Sorry, you cannot view this resource.",
    "data": {
        "status": 401
    }
}

我尝试使用来自另一个网站的 wp_remote_request 和 CURL 进行基本身份验证,但每次结果都相同。

id 为 3 的用户存在,我已经检查过了。如果我想列出所有用户,我只会得到那些创建了帖子的用户。

我已经激活了所需的插件:WP REST API、JSON Basic Authentication。

我的wordpress版本:4.4.2

【问题讨论】:

    标签: php wordpress rest authentication wordpress-rest-api


    【解决方案1】:

    最后,我找到了解决方案。我不得不手动向我的 .htaccess 文件添加一些新选项,但插件没有成功。

    代码:

    # BEGIN WP BASIC Auth
    <IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteBase /PluginTest/
    RewriteCond %{HTTP:Authorization} ^(.*)
    RewriteRule ^(.*) - [E=HTTP_AUTHORIZATION:%1]
    </IfModule>
    # END WP BASIC Auth
    

    【讨论】:

    • 太棒了!请记住使用 SSL,因为基本身份验证会在每个请求中发送用户的实际登录详细信息。长期看一下 JWT(JSON Web 令牌)wordpress.org/plugins/jwt-authentication-for-wp-rest-api
    • 我现在正在使用 Oauth1 身份验证,Basic 仅用于测试,我在使用 Oauth1 时遇到了同样的问题,所以这个 htaccess 也解决了这个问题。 :)
    • 酷 - 对于移动应用程序,我发现 JWT 更容易设置,但 Oauth 有效。我只是希望使用过的 Oauth 1a 或 2
    【解决方案2】:

    我认为问题不在于从服务器获取用户数据,但此错误代码是针对您的身份验证问题 拥有此用户权限或角色可能不是管理员

    查看详情

    wp-content/plugins/rest-api/lib/endpoints/class-wp-rest-users-controller.php

    public function get_item_permissions_check( $request ) {
    
        $id = (int) $request['id'];
        $user = get_userdata( $id );
        $types = get_post_types( array( 'public' => true ), 'names' );
    
        if ( empty( $id ) || empty( $user->ID ) ) {
            return new WP_Error( 'rest_user_invalid_id', __( 'Invalid resource id.' ), array( 'status' => 404 ) );
        }
    
        if ( get_current_user_id() === $id ) {
            return true;
        }
    
        if ( 'edit' === $request['context'] && ! current_user_can( 'list_users' ) ) {
            return new WP_Error( 'rest_user_cannot_view', __( 'Sorry, you cannot view this resource with edit context.' ), array( 'status' => rest_authorization_required_code() ) );
        } else if ( ! count_user_posts( $id, $types ) && ! current_user_can( 'edit_user', $id ) && ! current_user_can( 'list_users' ) ) {
            return new WP_Error( 'rest_user_cannot_view', __( 'Sorry, you cannot view this resource.' ), array( 'status' => rest_authorization_required_code() ) );
        }
    
        return true;
    }
    

    【讨论】:

    • 报错信息一样,正常调用,无需认证。即使我没有发送我的登录凭据,我也会收到此消息,这就是我认为这可能是身份验证问题的原因。附言我想出了另一件事。我在我的 localhost 上安装了一个全新的 wordpress,只安装了这 2 个插件,如果我使用“localhost”它仍然无法工作,但如果我使用我的本地 IP 地址“127.0.0.1”,则身份验证有效。
    • Fresh WordPress 可能未包含在 .htaccess 中,因此很明显它会引发错误,但对于您的项目,用户角色可能存在问题。
    • 我的管理员用户角色是“admin”,所以我无法更改它。正如我所提到的,如果我将 url 从 localhost/wp_test1/wp-json/wp/v2/users/2 更改为 127.0.0.1/wp_test1/wp-json/wp/v2/users/2,新的 wordpress 一切正常,身份验证工作,我可以用我的删除帖子管理员角色用户。
    【解决方案3】:

    对于所有面临这些错误的人,请删除标头中的基本身份验证授权,并在激活 JWT 后在所有情况下(获取和发布)发送 customer_key 和 customer_secret 作为查询参数。这可能看起来很奇怪且不安全,但它对我有用。

    【讨论】:

      猜你喜欢
      • 2013-05-30
      • 1970-01-01
      • 2017-09-18
      • 1970-01-01
      • 2016-03-24
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2017-06-13
      相关资源
      最近更新 更多