如何在FastSpring Webhook中携带自定义数据(如站点URL或用户ID)并在WordPress插件中实现?
如何在FastSpring Webhook中携带自定义数据(如站点URL或用户ID)并在WordPress插件中实现?
我来帮你一步步搞定这个需求,核心思路就是在触发FastSpring结账时把自定义数据传递过去,让FastSpring把这些数据包含在webhook请求里,最后在WordPress的webhook处理端提取出来。下面结合你现有的插件代码来具体实现:
一、在前端向FastSpring传递自定义数据
你的现有代码里已经有了触发结账的addVariationAndCheckout函数,我们可以在这个环节把站点URL和当前用户ID传给FastSpring。
首先修改你的employee_payment_manager_page函数,把WordPress的站点URL和当前用户ID安全输出到前端JS中:
function employee_payment_manager_page() { ob_start(); // 从WordPress获取站点URL和当前用户ID,转义后传给JS $site_url = esc_js(home_url()); $current_user_id = esc_js(get_current_user_id()); ?> <script id="fsc-api" src="https://d1f8f9xcsvx3ha.cloudfront.net/sbl/0.9.0/fastspring-builder.min.js" type="text/javascript" data-popup-webhook-received="dataPopupWebhookReceived" data-storefront="bwdplugins.test.onfastspring.com/popup-bwdplugins"> </script> <div class="wrap"> <h1>Payment Manager</h1> <p> <button onclick="addVariationAndCheckout('pcm-monthly')" class="wpcv-price-btn"> Pay Monthly per User </button> </p> </div> <script> const siteURL = '<?php echo $site_url; ?>'; const currentUserID = <?php echo $current_user_id; ?>; function dataPopupWebhookReceived(data) { console.log("Webhook received:", data); } function addVariationAndCheckout(variation) { fastspring.builder.reset(); switch (variation) { case 'pcm-monthly': fastspring.builder.add('pcm-monthly'); break; default: break; } // 添加自定义字段,把站点URL和用户ID传给FastSpring fastspring.builder.setCustomField('siteURL', siteURL); fastspring.builder.setCustomField('userID', currentUserID); fastspring.builder.checkout(); } </script> <?php echo ob_get_clean(); }
二、配置FastSpring确保自定义数据随Webhook发送
登录你的FastSpring后台,进入商店的Webhook设置:
- 确认你订阅的事件(比如
payment.completed)会包含自定义字段数据(FastSpring默认会把结账时传递的自定义字段放在webhook的custom对象里) - 确保你的webhook端点
https://example.com/wp-json/v1/webhook已经正确配置,且状态为活跃
三、在WordPress中实现Webhook处理端点,提取自定义数据
你现在的代码还没有webhook的处理逻辑,我们需要添加一个REST API端点来接收FastSpring的请求,并安全提取自定义数据:
/** * 注册FastSpring Webhook的REST API端点 */ add_action('rest_api_init', function () { register_rest_route( 'v1', '/webhook', array( 'methods' => 'POST', 'callback' => 'handle_fastspring_webhook', 'permission_callback' => '__return_true', // 后续一定要添加签名验证,暂时先开放 ) ); }); /** * 处理FastSpring Webhook请求 */ function handle_fastspring_webhook(WP_REST_Request $request) { // 1. 关键:验证FastSpring的Webhook签名,防止恶意请求 // 从FastSpring后台获取你的Webhook密钥,替换下面的占位符 $webhook_secret = 'YOUR_FASTSPRING_WEBHOOK_SECRET'; $signature = $request->get_header('X-FastSpring-Signature'); $payload = $request->get_body(); $expected_signature = hash_hmac('sha256', $payload, $webhook_secret); if (!hash_equals($expected_signature, $signature)) { return new WP_REST_Response('Invalid signature', 403); } // 2. 解析Webhook数据 $data = json_decode($payload, true); // 3. 提取我们传递的自定义数据 $site_url = isset($data['custom']['siteURL']) ? $data['custom']['siteURL'] : ''; $user_id = isset($data['custom']['userID']) ? $data['custom']['userID'] : ''; // 4. 在这里实现你的业务逻辑,比如更新用户订阅、保存订单记录等 // 示例:把数据保存到WordPress选项中 update_option('last_fastspring_order_site', $site_url); update_option('last_fastspring_order_user', $user_id); // 返回成功响应给FastSpring return new WP_REST_Response('Webhook processed successfully', 200); }
重要提醒
- 签名验证必须做:上面代码中的签名验证是核心安全措施,一定要从FastSpring后台获取你的Webhook密钥替换占位符,避免恶意请求伪造Webhook。
- 用户ID的特殊情况:如果用户未登录,
get_current_user_id()会返回0,你可以在前端判断用户登录状态,只有登录用户才显示结账按钮,或者在webhook处理逻辑中单独处理未登录场景。 - 数据安全:所有传递的自定义数据都用了
esc_js做转义处理,防止XSS攻击,这个习惯要保持。
内容来源于stack exchange
相关产品推荐
相关产品推荐

