You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在WordPress插件中获取FTP连接信息与凭据?

WordPress插件自动生成客户端FTP配置文件的实现思路

1. 复用WordPress内置的FTP凭据机制

WordPress本身在更新插件、主题或处理文件操作时,会允许用户输入FTP信息并存储到数据库中。你可以直接利用WP_Filesystem类来获取这些已存储的凭据,不用重复开发输入表单:

global $wp_filesystem;
// 初始化文件系统,若没有存储的凭据会自动弹出WordPress原生的FTP输入界面
if (!WP_Filesystem()) {
    return;
}

// 从WP_Filesystem中提取FTP连接信息
$ftp_host = $wp_filesystem->options['hostname'];
$ftp_user = $wp_filesystem->options['username'];
$ftp_pass = $wp_filesystem->options['password'];
$ftp_port = isset($wp_filesystem->options['port']) ? $wp_filesystem->options['port'] : 21;

这种方式的好处是完全复用WordPress原生的安全验证逻辑,不用自己处理凭据存储的安全性。

2. 自定义后台设置页面收集专属FTP配置

如果需要针对音频归档库的专属FTP配置(比如指定远程存储路径),可以在插件后台添加自定义设置页面:

  • 注册设置项并渲染表单字段:
add_action('admin_init', 'my_audio_plugin_register_ftp_settings');
function my_audio_plugin_register_ftp_settings() {
    register_setting(
        'audio_ftp_group', 
        'audio_ftp_config', 
        'sanitize_audio_ftp_settings'
    );
    
    add_settings_section(
        'audio_ftp_section', 
        '音频归档库FTP配置', 
        'audio_ftp_section_desc', 
        'audio_plugin_settings'
    );
    
    // 添加主机、端口、用户名、密码、远程路径等字段
    add_settings_field('ftp_host', 'FTP主机', 'render_ftp_host_field', 'audio_plugin_settings', 'audio_ftp_section');
    add_settings_field('ftp_port', 'FTP端口', 'render_ftp_port_field', 'audio_plugin_settings', 'audio_ftp_section');
    add_settings_field('ftp_user', 'FTP用户名', 'render_ftp_user_field', 'audio_plugin_settings', 'audio_ftp_section');
    add_settings_field('ftp_pass', 'FTP密码', 'render_ftp_pass_field', 'audio_plugin_settings', 'audio_ftp_section');
    add_settings_field('remote_path', '归档库远程路径', 'render_remote_path_field', 'audio_plugin_settings', 'audio_ftp_section');
}

// 示例字段渲染函数
function render_ftp_host_field() {
    $config = get_option('audio_ftp_config');
    echo '<input type="text" name="audio_ftp_config[ftp_host]" value="' . esc_attr($config['ftp_host'] ?? '') . '" class="regular-text" />';
}

// 输入验证与清理函数
function sanitize_audio_ftp_settings($input) {
    $sanitized = [];
    $sanitized['ftp_host'] = sanitize_text_field($input['ftp_host'] ?? '');
    $sanitized['ftp_port'] = (int)($input['ftp_port'] ?? 21);
    $sanitized['ftp_user'] = sanitize_text_field($input['ftp_user'] ?? '');
    $sanitized['remote_path'] = sanitize_text_field($input['remote_path'] ?? '/audio_archives/');
    
    // 加密密码后存储,避免明文泄露
    if (!empty($input['ftp_pass'])) {
        $sanitized['encrypted_pass'] = encrypt_ftp_password($input['ftp_pass']);
    } else {
        // 保留原有加密密码
        $existing_config = get_option('audio_ftp_config');
        $sanitized['encrypted_pass'] = $existing_config['encrypted_pass'] ?? '';
    }
    
    return $sanitized;
}

// 加密密码函数(基于WordPress密钥)
function encrypt_ftp_password($password) {
    $key = AUTH_KEY;
    $cipher = 'AES-256-CBC';
    $iv_length = openssl_cipher_iv_length($cipher);
    $iv = openssl_random_pseudo_bytes($iv_length);
    $encrypted = openssl_encrypt($password, $cipher, $key, 0, $iv);
    return base64_encode($iv . $encrypted);
}

3. 生成客户端配置文件

获取到有效FTP配置后,即可生成客户端所需的配置文件(比如JSON格式),支持下载或API接口返回:

// 生成并下载配置文件的函数
add_action('admin_post_generate_audio_config', 'generate_audio_client_config');
function generate_audio_client_config() {
    // 验证权限,仅管理员可操作
    if (!current_user_can('manage_options')) {
        wp_die('无权限访问');
    }
    
    $ftp_config = get_option('audio_ftp_config');
    if (empty($ftp_config['encrypted_pass'])) {
        wp_die('请先配置FTP密码');
    }
    
    // 解密密码
    $decrypted_pass = decrypt_ftp_password($ftp_config['encrypted_pass']);
    
    // 构造配置数据
    $config_data = [
        'ftp_host' => $ftp_config['ftp_host'],
        'ftp_port' => $ftp_config['ftp_port'],
        'ftp_user' => $ftp_config['ftp_user'],
        'ftp_password' => $decrypted_pass,
        'remote_archive_path' => $ftp_config['remote_path']
    ];
    
    // 输出JSON配置文件供下载
    header('Content-Type: application/json');
    header('Content-Disposition: attachment; filename="audio-client-config.json"');
    echo json_encode($config_data, JSON_PRETTY_PRINT);
    exit;
}

// 解密密码函数
function decrypt_ftp_password($encrypted_pass) {
    $key = AUTH_KEY;
    $cipher = 'AES-256-CBC';
    $decoded = base64_decode($encrypted_pass);
    $iv_length = openssl_cipher_iv_length($cipher);
    $iv = substr($decoded, 0, $iv_length);
    $encrypted_data = substr($decoded, $iv_length);
    return openssl_decrypt($encrypted_data, $cipher, $key, 0, $iv);
}

如果客户端是通过API获取配置,还可以注册一个REST路由,返回配置数据(建议搭配HTTPS保障传输安全)。

4. 关键安全注意事项

  • 密码加密存储:绝对不能将FTP密码明文存入数据库,必须用WordPress的AUTH_KEY作为密钥进行加密。
  • 权限控制:生成配置的接口或页面必须限制仅管理员角色访问,避免未授权获取敏感信息。
  • 连接验证:在用户提交FTP配置后,添加连接测试逻辑,确保配置有效:
function test_ftp_connection($host, $port, $user, $pass) {
    $conn = ftp_connect($host, $port, 30);
    if (!$conn) return false;
    $login_success = ftp_login($conn, $user, $pass);
    ftp_close($conn);
    return $login_success;
}
  • HTTPS传输:如果客户端通过API获取配置,必须使用HTTPS协议,防止配置信息在传输过程中被窃取。

内容的提问来源于stack exchange,提问作者Marley Plant

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 03:27:49