You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PrestaShop Webservice API实现客户登录并获取认证令牌?

PrestaShop与React集成:客户身份验证及令牌获取方案

核心结论

PrestaShop官方Webservice API没有原生提供客户登录及获取认证令牌的端点,需要通过自定义模块扩展API来实现该功能。

具体实现步骤

1. 创建PrestaShop自定义模块,添加登录验证端点

编写自定义模块,新增一个API端点处理客户登录请求,核心逻辑包括凭据验证、令牌生成:

模块核心代码示例

<?php
if (!defined('_PS_VERSION_')) {
    exit;
}

class CustomCustomerAuth extends Module
{
    public function __construct()
    {
        $this->name = 'customcustomerauth';
        $this->tab = 'front_office_features';
        $this->version = '1.0.0';
        $this->author = 'Your Name';
        $this->need_instance = 0;
        $this->bootstrap = true;

        parent::__construct();

        $this->displayName = $this->l('Custom Customer Authentication');
        $this->description = $this->l('Adds API endpoint for customer login and JWT token generation');
    }

    public function install()
    {
        return parent::install() && $this->registerHook('actionDispatcher');
    }

    public function hookActionDispatcher()
    {
        $route = $_SERVER['REQUEST_URI'];
        // 定义登录端点路径
        if (strpos($route, '/api/customer/login') !== false && $_SERVER['REQUEST_METHOD'] === 'POST') {
            $this->handleCustomerLogin();
            exit;
        }
    }

    private function handleCustomerLogin()
    {
        header('Content-Type: application/json');
        $postData = json_decode(file_get_contents('php://input'), true);

        if (!isset($postData['email']) || !isset($postData['password'])) {
            http_response_code(400);
            echo json_encode(['error' => 'Email and password are required']);
            return;
        }

        // 验证客户凭据
        $customer = new Customer();
        $authenticationResult = $customer->getByEmail($postData['email'], $postData['password']);

        if (!$authenticationResult) {
            http_response_code(401);
            echo json_encode(['error' => 'Invalid credentials']);
            return;
        }

        // 生成JWT令牌(需通过composer安装firebase/php-jwt库)
        require_once $this->getLocalPath() . 'vendor/autoload.php';
        use Firebase\JWT\JWT;

        $secretKey = 'your_strong_random_secret_key'; // 替换为安全密钥,建议存于PrestaShop配置
        $payload = [
            'iss' => $_SERVER['HTTP_HOST'],
            'sub' => $customer->id,
            'email' => $customer->email,
            'exp' => time() + 3600 // 令牌有效期1小时
        ];

        $jwt = JWT::encode($payload, $secretKey, 'HS256');

        echo json_encode([
            'token' => $jwt,
            'customer' => [
                'id' => $customer->id,
                'firstname' => $customer->firstname,
                'lastname' => $customer->lastname,
                'email' => $customer->email
            ]
        ]);
    }
}

配置说明

  • 在模块目录执行composer require firebase/php-jwt安装JWT依赖
  • 务必替换your_strong_random_secret_key为高复杂度随机密钥,避免硬编码,可存入PrestaShop后台配置项

2. React端实现登录请求

创建登录表单,发送POST请求到自定义端点获取令牌并存储:

const handleLogin = async (email, password) => {
  try {
    const response = await fetch('https://your-prestashop-domain/api/customer/login', {
      method: 'POST',
      headers: {
        'Content-Type': 'application/json',
      },
      body: JSON.stringify({ email, password }),
    });

    if (!response.ok) {
      const errorData = await response.json();
      throw new Error(errorData.error || 'Login failed');
    }

    const data = await response.json();
    // 将令牌存储在localStorage或安全cookie中
    localStorage.setItem('customer_token', data.token);
    // 处理登录成功逻辑,如跳转客户中心
    console.log('Login successful', data.customer);
  } catch (error) {
    console.error('Login error:', error.message);
    // 向用户展示错误提示
  }
};

3. 令牌验证与后续请求处理

在自定义模块中添加令牌验证逻辑,用于保护需要认证的API端点:

令牌验证代码示例

private function validateToken()
{
    if (!isset($_SERVER['HTTP_AUTHORIZATION'])) {
        http_response_code(401);
        echo json_encode(['error' => 'Authorization header missing']);
        exit;
    }

    $authHeader = $_SERVER['HTTP_AUTHORIZATION'];
    $token = str_replace('Bearer ', '', $authHeader);

    $secretKey = 'your_strong_random_secret_key';
    try {
        $decoded = JWT::decode($token, $secretKey, ['HS256']);
        // 验证客户有效性
        $customer = new Customer($decoded->sub);
        if (!$customer->id) {
            throw new Exception('Invalid customer');
        }
        return $customer;
    } catch (Exception $e) {
        http_response_code(401);
        echo json_encode(['error' => 'Invalid or expired token']);
        exit;
    }
}

后续在需要认证的自定义API端点中,先调用$this->validateToken()即可获取当前登录的客户实例,执行对应业务逻辑。

替代方案(不推荐生产环境)

若不想使用JWT,可模拟前端登录流程获取PrestaShop客户Cookie,但跨域场景需配置CORS,且安全性较低,仅适合测试场景。


内容的提问来源于stack exchange,提问作者SpritS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 02:52:37