如何在WordPress插件中获取FTP连接信息与凭据?
WordPress插件自动生成客户端FTP配置文件的实现思路
1. 复用WordPress内置的FTP凭据机制
WordPress本身在更新插件、主题或处理文件操作时,会允许用户输入FTP信息并存储到数据库中。你可以直接利用WP_Filesystem类来获取这些已存储的凭据,不用重复开发输入表单:
global $wp_filesystem; // 初始化文件系统,若没有存储的凭据会自动弹出WordPress原生的FTP输入界面 if (!WP_Filesystem()) { return; } // 从WP_Filesystem中提取FTP连接信息 $ftp_host = $wp_filesystem->options['hostname']; $ftp_user = $wp_filesystem->options['username']; $ftp_pass = $wp_filesystem->options['password']; $ftp_port = isset($wp_filesystem->options['port']) ? $wp_filesystem->options['port'] : 21;
这种方式的好处是完全复用WordPress原生的安全验证逻辑,不用自己处理凭据存储的安全性。
2. 自定义后台设置页面收集专属FTP配置
如果需要针对音频归档库的专属FTP配置(比如指定远程存储路径),可以在插件后台添加自定义设置页面:
- 注册设置项并渲染表单字段:
add_action('admin_init', 'my_audio_plugin_register_ftp_settings'); function my_audio_plugin_register_ftp_settings() { register_setting( 'audio_ftp_group', 'audio_ftp_config', 'sanitize_audio_ftp_settings' ); add_settings_section( 'audio_ftp_section', '音频归档库FTP配置', 'audio_ftp_section_desc', 'audio_plugin_settings' ); // 添加主机、端口、用户名、密码、远程路径等字段 add_settings_field('ftp_host', 'FTP主机', 'render_ftp_host_field', 'audio_plugin_settings', 'audio_ftp_section'); add_settings_field('ftp_port', 'FTP端口', 'render_ftp_port_field', 'audio_plugin_settings', 'audio_ftp_section'); add_settings_field('ftp_user', 'FTP用户名', 'render_ftp_user_field', 'audio_plugin_settings', 'audio_ftp_section'); add_settings_field('ftp_pass', 'FTP密码', 'render_ftp_pass_field', 'audio_plugin_settings', 'audio_ftp_section'); add_settings_field('remote_path', '归档库远程路径', 'render_remote_path_field', 'audio_plugin_settings', 'audio_ftp_section'); } // 示例字段渲染函数 function render_ftp_host_field() { $config = get_option('audio_ftp_config'); echo '<input type="text" name="audio_ftp_config[ftp_host]" value="' . esc_attr($config['ftp_host'] ?? '') . '" class="regular-text" />'; } // 输入验证与清理函数 function sanitize_audio_ftp_settings($input) { $sanitized = []; $sanitized['ftp_host'] = sanitize_text_field($input['ftp_host'] ?? ''); $sanitized['ftp_port'] = (int)($input['ftp_port'] ?? 21); $sanitized['ftp_user'] = sanitize_text_field($input['ftp_user'] ?? ''); $sanitized['remote_path'] = sanitize_text_field($input['remote_path'] ?? '/audio_archives/'); // 加密密码后存储,避免明文泄露 if (!empty($input['ftp_pass'])) { $sanitized['encrypted_pass'] = encrypt_ftp_password($input['ftp_pass']); } else { // 保留原有加密密码 $existing_config = get_option('audio_ftp_config'); $sanitized['encrypted_pass'] = $existing_config['encrypted_pass'] ?? ''; } return $sanitized; } // 加密密码函数(基于WordPress密钥) function encrypt_ftp_password($password) { $key = AUTH_KEY; $cipher = 'AES-256-CBC'; $iv_length = openssl_cipher_iv_length($cipher); $iv = openssl_random_pseudo_bytes($iv_length); $encrypted = openssl_encrypt($password, $cipher, $key, 0, $iv); return base64_encode($iv . $encrypted); }
3. 生成客户端配置文件
获取到有效FTP配置后,即可生成客户端所需的配置文件(比如JSON格式),支持下载或API接口返回:
// 生成并下载配置文件的函数 add_action('admin_post_generate_audio_config', 'generate_audio_client_config'); function generate_audio_client_config() { // 验证权限,仅管理员可操作 if (!current_user_can('manage_options')) { wp_die('无权限访问'); } $ftp_config = get_option('audio_ftp_config'); if (empty($ftp_config['encrypted_pass'])) { wp_die('请先配置FTP密码'); } // 解密密码 $decrypted_pass = decrypt_ftp_password($ftp_config['encrypted_pass']); // 构造配置数据 $config_data = [ 'ftp_host' => $ftp_config['ftp_host'], 'ftp_port' => $ftp_config['ftp_port'], 'ftp_user' => $ftp_config['ftp_user'], 'ftp_password' => $decrypted_pass, 'remote_archive_path' => $ftp_config['remote_path'] ]; // 输出JSON配置文件供下载 header('Content-Type: application/json'); header('Content-Disposition: attachment; filename="audio-client-config.json"'); echo json_encode($config_data, JSON_PRETTY_PRINT); exit; } // 解密密码函数 function decrypt_ftp_password($encrypted_pass) { $key = AUTH_KEY; $cipher = 'AES-256-CBC'; $decoded = base64_decode($encrypted_pass); $iv_length = openssl_cipher_iv_length($cipher); $iv = substr($decoded, 0, $iv_length); $encrypted_data = substr($decoded, $iv_length); return openssl_decrypt($encrypted_data, $cipher, $key, 0, $iv); }
如果客户端是通过API获取配置,还可以注册一个REST路由,返回配置数据(建议搭配HTTPS保障传输安全)。
4. 关键安全注意事项
- 密码加密存储:绝对不能将FTP密码明文存入数据库,必须用WordPress的
AUTH_KEY作为密钥进行加密。 - 权限控制:生成配置的接口或页面必须限制仅管理员角色访问,避免未授权获取敏感信息。
- 连接验证:在用户提交FTP配置后,添加连接测试逻辑,确保配置有效:
function test_ftp_connection($host, $port, $user, $pass) { $conn = ftp_connect($host, $port, 30); if (!$conn) return false; $login_success = ftp_login($conn, $user, $pass); ftp_close($conn); return $login_success; }
- HTTPS传输:如果客户端通过API获取配置,必须使用HTTPS协议,防止配置信息在传输过程中被窃取。
内容的提问来源于stack exchange,提问作者Marley Plant
相关产品推荐
相关产品推荐

