You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WordPress REST API验证误判数组为空 嵌套参数验证不触发

问题成因
  1. 参数来源不匹配
    WordPress REST API 原生参数验证逻辑默认仅从查询参数(GET URL参数)、application/x-www-form-urlencoded/multipart/form-data格式的POST表单参数中读取参数值。如果你请求时传递的是application/json格式的请求体,验证阶段默认不会解析JSON内容,导致校验时读取不到users参数、判定为空,自然不会触发嵌套字段的校验回调,只有进入主回调调用get_body_params()方法时才会触发JSON解析,拿到正确的参数内容。
  2. 嵌套结构校验规则的适配问题
    低于5.6版本的WordPress,原生REST校验逻辑不支持items下嵌套properties的自动校验,即使外层参数正常读取,也不会自动遍历数组元素的属性触发对应的validate_callback。
  3. 验证回调返回值缺失
    如果validate_callback没有明确返回布尔值true,即使被触发也会被系统判定为验证失败,部分场景下会导致日志输出被截断。
解决方案
  1. 调整路由配置明确参数来源
    在路由注册的配置项中新增param_order参数,指定校验时优先读取请求体内容,同时补充验证回调的返回值,示例配置如下:
[
    'methods' => ['POST', 'GET'],
    // 优先读取JSON请求体,再依次读取查询参数、表单参数
    'param_order' => [ 'body', 'query', 'post' ],
    'args' =>
    [
        'users' =>
        [
            'type' => 'array',
            'required' => true, // 明确该参数为必填
            'minItems' => 1,
            'items' =>
            [
                'type' => 'object',
                'properties' =>
                [
                    'user_login' =>
                    [
                        'type' => 'string',
                        'required' => true,
                        'validate_callback' => function($user_login)
                        {
                            error_log("login validation");
                            // 验证回调必须返回布尔值/WP_Error,返回false/WP_Error会直接拦截请求
                            return true;
                        }
                    ],
                    'user_email' =>
                    [
                        'type' => 'string',
                        'required' => false,
                        'validate_callback' => function($user_email)
                        {
                            error_log("email validation");
                            return true;
                        }
                    ]
                ]
            ]
        ]
    ],
    'callback' => function($request)
    {
        return $request->get_body_params();
    }
]
  1. 低版本WordPress兼容处理
    如果使用的WordPress版本低于5.6,无法自动触发嵌套属性的校验,可以在外层users参数的validate_callback中手动遍历数组元素,执行对应的校验逻辑,示例如下:
'users' => [
    'type' => 'array',
    'required' => true,
    'minItems' => 1,
    'validate_callback' => function($users, $request, $param) {
        foreach ($users as $index => $user) {
            // 校验user_login
            if (empty($user['user_login']) || !is_string($user['user_login'])) {
                return new WP_Error('rest_invalid_user_login', sprintf('第%d个用户的user_login参数无效', $index + 1), [ 'status' => 400 ]);
            }
            error_log("login validation for user {$index}");
            // 校验user_email
            if (isset($user['user_email']) && !is_string($user['user_email'])) {
                return new WP_Error('rest_invalid_user_email', sprintf('第%d个用户的user_email参数无效', $index + 1), [ 'status' => 400 ]);
            }
            if (isset($user['user_email'])) {
                error_log("email validation for user {$index}");
            }
        }
        return true;
    }
]
  1. 确认请求配置
    发送POST请求时必须正确设置请求头Content-Type: application/json,否则WordPress不会将请求体识别为JSON格式,无法解析出对应的参数。如果使用GET请求,不支持传递JSON请求体,需要将参数编码后放到URL查询参数中。

内容的提问来源于stack exchange,提问作者Kenny

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.01 13:09:05