如何通过WordPress REST API创建分类?遇403权限错误
我已尝试搜索但未找到对应解决方案。我可以通过以下PHP代码成功创建新标签:
<?php function wpAutoPoster($token,$endpointUrl,$data){ $curl = curl_init(); curl_setopt_array($curl, array( CURLOPT_URL => $endpointUrl, CURLOPT_RETURNTRANSFER => true, CURLOPT_ENCODING => '', CURLOPT_MAXREDIRS => 10, CURLOPT_TIMEOUT => 0, CURLOPT_FOLLOWLOCATION => true, CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1, CURLOPT_CUSTOMREQUEST => 'POST', CURLOPT_POSTFIELDS => $data, CURLOPT_HTTPHEADER => array( 'Content-Type: application/json', 'accept: application/json', 'Authorization: Bearer '.$token ), )); $response = curl_exec($curl); curl_close($curl); return $response; } $jwtAuthToken="xxx"; $endpointUrl="https://www.example.com/wp-json/wp/v2/tags"; $data=json_encode(['name'=>'my new tag 1']); $response=json_decode(wpAutoPoster($jwtAuthToken,$endpointUrl,$data)); var_dump($response);
上述代码可正常运行。但当我修改以下两行代码尝试创建分类时:
$endpointUrl="https://www.example.com/wp-json/wp/v2/categories"; $data=json_encode(['name'=>'my new category 1'])
却收到如下错误响应:
object(stdClass)#1 (3) { ["code"]=> string(18) "rest_cannot_create" ["message"]=> string(60) "Sorry, you are not allowed to create terms in this taxonomy." ["data"]=> object(stdClass)#2 (1) { ["status"]=> int(403) }
自定义文章类型(Custom Post Types)也存在同样问题,设置'hierarchical' => true后错误依旧。请问如何解决?
1. 验证JWT对应用户的权限
创建分类需要用户具备manage_categories权限(默认管理员、编辑者角色拥有),而标签仅需manage_post_tags权限(作者及以上角色即可)。需确认JWT令牌对应的用户角色权限:
- 登录WordPress后台,查看该用户的角色设置,确认勾选了管理分类权限。
- 携带JWT令牌调用
/wp/v2/users/me接口,返回的capabilities字段会显示用户所有权限,检查是否包含manage_categories。
2. 检查自定义分类法的REST API配置
如果是自定义文章类型的分类(自定义分类法),注册时必须开启REST API支持并正确配置权限:
register_taxonomy( 'your_custom_taxonomy', 'your_custom_post_type', array( 'hierarchical' => true, 'show_in_rest' => true, // 必须开启才能通过REST API操作 'rest_base' => 'your-custom-taxonomy', // 设置REST端点基础路径 'capabilities' => array( 'manage_terms' => 'manage_categories', // 可根据需求调整对应权限 'edit_terms' => 'manage_categories', 'delete_terms' => 'manage_categories', 'assign_terms' => 'edit_posts', ), // 其他配置项 ) );
注意:show_in_rest设为true是分类法支持REST API的必要条件。
3. 排查REST API权限回调的修改
部分主题或插件可能修改了REST API的权限回调,导致分类创建被拦截。可在主题functions.php或自定义插件中添加以下代码,强制配置分类法的REST创建权限:
add_filter('rest_term_collection_params', function($params, $taxonomy) { // 针对需要开放的分类法调整,比如默认分类或自定义分类 if ($taxonomy === 'category' || $taxonomy === 'your_custom_taxonomy') { $params['create'] = current_user_can('manage_categories'); } return $params; }, 10, 2); add_filter('rest_pre_insert_term', function($prepared_term, $taxonomy) { if ($taxonomy === 'category' || $taxonomy === 'your_custom_taxonomy') { if (!current_user_can('manage_categories')) { return new WP_Error('rest_cannot_create', 'Sorry, you are not allowed to create terms in this taxonomy.', array('status' => 403)); } } return $prepared_term; }, 10, 2);
4. 检查JWT插件的权限限制
若使用JWT Authentication for WP REST API插件,需确认插件配置:
- 检查插件设置,确保未开启“仅允许管理员使用JWT”类限制选项。
- 确认JWT令牌生成时,用户的角色和权限被正确包含(插件默认会包含)。
5. 调试权限检查结果
可添加临时代码到WordPress中,查看用户权限的实际情况:
add_action('rest_api_init', function() { add_action('wp_loaded', function() { error_log('Current user can manage categories: ' . current_user_can('manage_categories')); error_log('Current user roles: ' . print_r(wp_get_current_user()->roles, true)); }); });
然后查看服务器PHP错误日志,确认用户是否真的拥有对应权限。
内容的提问来源于stack exchange,提问作者John Collins

