You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PrestaShop 1.7 API访问问题:.htaccess与API密钥认证冲突

问题描述

我正尝试访问PrestaShop的API,但我的PrestaShop站点受.htaccess保护。查阅PrestaShop官方文档后发现,问题在于PrestaShop使用的基础认证与.htaccess的认证机制冲突。

我尝试使用以下URL:

https://test:test@example.com/api/categories

并添加HTTP请求头:Authorization : Basic <apikey>

但收到如下错误响应:

Unauthorized

This server could not verify that you are authorized to access the document requested. Either you supplied the wrong credentials (e.g., bad password), or your browser doesn't understand how to supply the credentials required.

Additionally, a 401 Unauthorized error was encountered while trying to use an ErrorDocument to handle the request.

请问如何同时实现.htaccess认证与API密钥认证?注:我使用的是最新版本的PrestaShop 1.7。

解决方案

要同时兼容.htaccess基础认证和PrestaShop API密钥认证,可通过以下几种方式处理:

方法1:为API路径跳过.htaccess认证

在站点的.htaccess文件中,找到基础认证的配置块(通常包含AuthType Basic、AuthName、AuthUserFile指令),添加例外规则让API路径跳过.htaccess认证:

# 原有.htaccess认证配置
AuthType Basic
AuthName "Protected Area"
AuthUserFile /path/to/your/.htpasswd
Require valid-user

# 为API路径设置认证例外
SetEnvIf Request_URI "^/api/" allow_api=1
Order deny,allow
Deny from all
Allow from env=allow_api
Satisfy any

配置后,访问/api/开头的路径时会跳过.htaccess认证,只需携带PrestaShop的API密钥头即可正常调用接口。

方法2:传递双重认证凭据

如果不想跳过API路径的.htaccess认证,可通过分离认证头的方式传递两种凭据:

  • URL中携带.htaccess的用户名和密码:https://test:test@example.com/api/categories
  • 使用PrestaShop支持的自定义头PS_AUTH_KEY传递API密钥,请求头格式为:PS_AUTH_KEY: <你的API密钥>

服务器会先验证.htaccess的凭据,再由PrestaShop读取PS_AUTH_KEY头完成API权限验证。

方法3:修改PrestaShop的API认证头

通过后台配置修改API使用的认证头,避免与.htaccess的Authorization头冲突:

  1. 登录PrestaShop后台,进入高级参数 > 性能
  2. 在HTTP头区域找到API认证头选项,修改为自定义名称(比如X-PS-API-KEY)
  3. 保存配置后,请求API时用自定义头传递API密钥,同时通过URL或Authorization头传递.htaccess凭据

内容的提问来源于stack exchange,提问作者Toothgip

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 18:15:00