You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过WordPress REST API创建分类?遇403权限错误

问题描述

我已尝试搜索但未找到对应解决方案。我可以通过以下PHP代码成功创建新标签:

<?php
function wpAutoPoster($token,$endpointUrl,$data){
$curl = curl_init();

curl_setopt_array($curl, array(
  CURLOPT_URL => $endpointUrl,
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_ENCODING => '',
  CURLOPT_MAXREDIRS => 10,
  CURLOPT_TIMEOUT => 0,
  CURLOPT_FOLLOWLOCATION => true,
  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
  CURLOPT_CUSTOMREQUEST => 'POST',
  CURLOPT_POSTFIELDS => $data,
  CURLOPT_HTTPHEADER => array(
    'Content-Type: application/json',
    'accept: application/json',
    'Authorization: Bearer '.$token
  ),
));

$response = curl_exec($curl);

curl_close($curl);
return $response;
}


$jwtAuthToken="xxx";


$endpointUrl="https://www.example.com/wp-json/wp/v2/tags";
$data=json_encode(['name'=>'my new tag 1']);

$response=json_decode(wpAutoPoster($jwtAuthToken,$endpointUrl,$data));

var_dump($response);

上述代码可正常运行。但当我修改以下两行代码尝试创建分类时:

$endpointUrl="https://www.example.com/wp-json/wp/v2/categories";
$data=json_encode(['name'=>'my new category 1'])

却收到如下错误响应:

object(stdClass)#1 (3) { ["code"]=> string(18) "rest_cannot_create" ["message"]=> string(60) "Sorry, you are not allowed to create terms in this taxonomy." ["data"]=> object(stdClass)#2 (1) { ["status"]=> int(403) }

自定义文章类型(Custom Post Types)也存在同样问题,设置'hierarchical' => true后错误依旧。请问如何解决?

解决方案

1. 验证JWT对应用户的权限

创建分类需要用户具备manage_categories权限(默认管理员、编辑者角色拥有),而标签仅需manage_post_tags权限(作者及以上角色即可)。需确认JWT令牌对应的用户角色权限:

  • 登录WordPress后台,查看该用户的角色设置,确认勾选了管理分类权限。
  • 携带JWT令牌调用/wp/v2/users/me接口,返回的capabilities字段会显示用户所有权限,检查是否包含manage_categories。

2. 检查自定义分类法的REST API配置

如果是自定义文章类型的分类(自定义分类法),注册时必须开启REST API支持并正确配置权限:

register_taxonomy(
    'your_custom_taxonomy',
    'your_custom_post_type',
    array(
        'hierarchical' => true,
        'show_in_rest' => true, // 必须开启才能通过REST API操作
        'rest_base' => 'your-custom-taxonomy', // 设置REST端点基础路径
        'capabilities' => array(
            'manage_terms' => 'manage_categories', // 可根据需求调整对应权限
            'edit_terms' => 'manage_categories',
            'delete_terms' => 'manage_categories',
            'assign_terms' => 'edit_posts',
        ),
        // 其他配置项
    )
);

注意:show_in_rest设为true是分类法支持REST API的必要条件。

3. 排查REST API权限回调的修改

部分主题或插件可能修改了REST API的权限回调,导致分类创建被拦截。可在主题functions.php或自定义插件中添加以下代码,强制配置分类法的REST创建权限:

add_filter('rest_term_collection_params', function($params, $taxonomy) {
    // 针对需要开放的分类法调整,比如默认分类或自定义分类
    if ($taxonomy === 'category' || $taxonomy === 'your_custom_taxonomy') {
        $params['create'] = current_user_can('manage_categories');
    }
    return $params;
}, 10, 2);

add_filter('rest_pre_insert_term', function($prepared_term, $taxonomy) {
    if ($taxonomy === 'category' || $taxonomy === 'your_custom_taxonomy') {
        if (!current_user_can('manage_categories')) {
            return new WP_Error('rest_cannot_create', 'Sorry, you are not allowed to create terms in this taxonomy.', array('status' => 403));
        }
    }
    return $prepared_term;
}, 10, 2);

4. 检查JWT插件的权限限制

若使用JWT Authentication for WP REST API插件,需确认插件配置:

  • 检查插件设置,确保未开启“仅允许管理员使用JWT”类限制选项。
  • 确认JWT令牌生成时,用户的角色和权限被正确包含(插件默认会包含)。

5. 调试权限检查结果

可添加临时代码到WordPress中,查看用户权限的实际情况:

add_action('rest_api_init', function() {
    add_action('wp_loaded', function() {
        error_log('Current user can manage categories: ' . current_user_can('manage_categories'));
        error_log('Current user roles: ' . print_r(wp_get_current_user()->roles, true));
    });
});

然后查看服务器PHP错误日志,确认用户是否真的拥有对应权限。

内容的提问来源于stack exchange,提问作者John Collins

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 16:51:33