如何为自定义WooCommerce API端点单独禁用认证?
Got it, let's tackle this problem step by step. Here's how you can disable WooCommerce's default auth for your specific custom endpoint and implement your own key-based authentication instead:
We'll split this into two core tasks: bypassing WooCommerce's default auth only for your target endpoint and adding custom key validation to secure that endpoint.
1. Disable WooCommerce Default Authentication for Your Endpoint
WooCommerce uses the woocommerce_rest_check_authentication filter to enforce its default consumer key/secret auth. We can hook into this filter to skip that check exclusively for your custom order creation endpoint.
Add this to your plugin file:
add_filter('woocommerce_rest_check_authentication', 'skip_woocommerce_auth_for_custom_order_endpoint', 10, 3); function skip_woocommerce_auth_for_custom_order_endpoint($auth_result, $consumer_key, $consumer_secret) { // Grab the current request object $request = wp_rest_server()->get_current_request(); if (!$request) return $auth_result; // Replace this with YOUR actual custom endpoint route (e.g., '/wc/v3/custom/create-order') $target_endpoint = '/wc/v3/custom/create-order'; // Check if the request is hitting our target endpoint if ($request->get_route() === $target_endpoint) { // Return true to skip WooCommerce's default auth check return true; } // Leave default auth intact for all other endpoints return $auth_result; }
2. Add Custom Key Validation for Your Endpoint
Next, we need to validate the custom key sent by the external platform (this can be a POST field, GET parameter, or part of the request body). We'll use the rest_pre_dispatch action to run this check before the endpoint processes the request.
Add this snippet right after the previous code:
add_action('rest_pre_dispatch', 'validate_custom_api_key_for_order_endpoint', 10, 3); function validate_custom_api_key_for_order_endpoint($result, $server, $request) { // Target only our custom order endpoint $target_endpoint = '/wc/v3/custom/create-order'; if ($request->get_route() !== $target_endpoint) { return $result; // Skip validation for other endpoints } // Fetch the custom key from the request (adjust the parameter name to match your external platform's field) $custom_key = $request->get_param('external_api_key'); // Store your valid key securely (never hardcode it directly in the plugin! Use wp-config.php instead) $valid_custom_key = CUSTOM_ORDER_API_KEY; // Validate the key if (empty($custom_key) || $custom_key !== $valid_custom_key) { // Return an unauthorized error if the key is missing or invalid return new WP_Error( 'rest_forbidden', __('Invalid or missing custom API key.', 'your-plugin-text-domain'), array('status' => 401) ); } // If validation passes, let the request proceed to your endpoint logic return $result; }
3. Securely Store Your Custom Key
Never hardcode your secret key in the plugin file! Add this to your wp-config.php instead:
// Add this line to wp-config.php (replace with a long, random secure key) define('CUSTOM_ORDER_API_KEY', 'your-super-secure-random-key-here');
How It All Works
- The first function checks if the request is for your custom endpoint and skips WooCommerce's default auth only when that's true.
- The second function runs before the endpoint executes, verifies the custom key is valid, and blocks the request with a 401 error if not.
- All other WooCommerce API endpoints will still use the default consumer key/secret authentication as expected.
Just remember to replace '/wc/v3/custom/create-order' with your actual endpoint route, and adjust the parameter name external_api_key to match what your external platform sends in the request.
内容的提问来源于stack exchange,提问作者Amjad

