WordPress:能否在非functions.php文件用get_theme_mod()获取定制器配置值
get_theme_mod()获取定制器配置值 Absolutely, this is totally doable! Your approach makes perfect sense—letting non-technical users configure API keys via the Customizer without touching code is exactly what the Customizer is designed for. Here's how to pull it off step by step:
1. 先在主题的functions.php中注册定制器设置
First, you need to add the Customizer controls for your API key and Place ID. Drop this code into your theme's functions.php file:
function custom_api_settings_customize_register($wp_customize) { // 添加自定义配置面板 $wp_customize->add_panel('api_settings_panel', array( 'title' => __('API Settings', 'your-theme'), 'priority' => 30, 'description' => __('Set up API keys for site integrations like Google Maps', 'your-theme'), )); // 添加Google Maps API专属章节 $wp_customize->add_section('google_maps_api_section', array( 'title' => __('Google Maps API', 'your-theme'), 'panel' => 'api_settings_panel', 'priority' => 10, )); // 注册API密钥设置项 $wp_customize->add_setting('google_maps_api_key', array( 'default' => '', 'sanitize_callback' => 'sanitize_text_field', 'transport' => 'refresh', )); // 添加API密钥输入框 $wp_customize->add_control('google_maps_api_key', array( 'label' => __('Google Maps API Key', 'your-theme'), 'section' => 'google_maps_api_section', 'type' => 'text', 'description' => __('Paste your Google Maps API key here', 'your-theme'), )); // 注册Place ID设置项 $wp_customize->add_setting('google_maps_place_id', array( 'default' => '', 'sanitize_callback' => 'sanitize_text_field', 'transport' => 'refresh', )); // 添加Place ID输入框 $wp_customize->add_control('google_maps_place_id', array( 'label' => __('Google Place ID', 'your-theme'), 'section' => 'google_maps_api_section', 'type' => 'text', 'description' => __('Enter your target Google Place ID here', 'your-theme'), )); } add_action('customize_register', 'custom_api_settings_customize_register');
Note: Replace your-theme with your actual theme slug, or remove the translation strings if you don't need multi-language support.
2. 在独立PHP文件中加载WordPress环境
Your standalone PHP file doesn't load WordPress by default, so you need to initialize the WP environment first to access functions like get_theme_mod(). Add this at the very top of your cURL file:
// Adjust the path to wp-load.php based on where your file is stored // Example: If your file is in /wp-content/themes/your-theme/api/ require_once('../../wp-load.php'); // Optional but recommended: Add nonce validation for AJAX requests // If you're calling this file via AJAX, pass a nonce from your JS and validate it here check_ajax_referer('google_maps_api_nonce', 'nonce');
Double-check the path to wp-load.php—you may need to adjust the number of ../ to reach your WordPress root directory.
3. 修改cURL代码,用get_theme_mod()获取配置值
Now you can replace your hardcoded API key and Place ID with dynamic values from the Customizer. Here's your updated cURL code:
// Pull values from the Customizer (second argument is a fallback empty string) $api_key = get_theme_mod('google_maps_api_key', ''); $place_id = get_theme_mod('google_maps_place_id', ''); // Validate values before making the API call if (empty($api_key) || empty($place_id)) { echo json_encode(array('error' => 'Missing API Key or Place ID. Please configure them in the Customizer.')); exit; } $curl = curl_init(); curl_setopt_array($curl, array( CURLOPT_URL => "https://maps.googleapis.com/maps/api/place/details/json?placeid={$place_id}&key={$api_key}", CURLOPT_RETURNTRANSFER => true, CURLOPT_ENCODING => "", CURLOPT_MAXREDIRS => 10, CURLOPT_TIMEOUT => 30, CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1, CURLOPT_CUSTOMREQUEST => "GET", CURLOPT_HTTPHEADER => array( "Cache-Control: no-cache", "Content-Type: application/json" ), )); $response = curl_exec($curl); $err = curl_error($curl); curl_close($curl); if ($err) { echo json_encode(array('error' => "cURL Error #: {$err}")); } else { echo $response; }
I added a quick validation step to catch empty values early, and formatted error responses as JSON to make it easier for your JS to handle.
4. Quick Security Tips
- Store your standalone file in a subfolder of your theme (not the root directory) to reduce accidental public access
- Always use nonce validation for AJAX requests to prevent CSRF attacks
- Consider wrapping the file in a check to ensure it's only accessed via your AJAX call, not direct browser requests
内容的提问来源于stack exchange,提问作者Vladimir Mujakovic

