如何将API调用生成的令牌存储到WordPress的MySQL数据库中
Hey there! Let's break down the simplest, most WordPress-friendly ways to store your access_token and refresh_token—no need to struggle with mimicking core registration code, since WordPress has built-in tools designed exactly for this kind of task.
Option 1: Site-Wide Tokens (Use WordPress Options API)
If these tokens are for your entire site (not tied to individual users), the Options API is your best bet. It handles database safety, serialization, and retrieval automatically.
Store the Tokens
Add this function to your theme's functions.php file or a custom plugin:
// Save payment gateway tokens to site options function save_payment_gateway_tokens($access_token, $refresh_token) { // Store access token (creates the option if it doesn't exist) update_option('payment_gateway_access_token', $access_token); // Store refresh token update_option('payment_gateway_refresh_token', $refresh_token); // Optional: Add token expiration if your provider includes one // update_option('payment_gateway_token_expiry', time() + (3600 * 24)); // 24-hour example } // Call this function once you have your tokens // save_payment_gateway_tokens('your_actual_access_token', 'your_actual_refresh_token');
Retrieve the Tokens Later
When you need to use the tokens for API calls:
// Fetch stored payment gateway tokens function get_payment_gateway_tokens() { return array( 'access_token' => get_option('payment_gateway_access_token'), 'refresh_token' => get_option('payment_gateway_refresh_token'), // 'expiry' => get_option('payment_gateway_token_expiry') ); } // Usage example // $tokens = get_payment_gateway_tokens(); // $access_token = $tokens['access_token'];
Option 2: User-Specific Tokens (Use User Meta API)
If each user has their own set of tokens (e.g., after linking their account to the payment gateway), use the User Meta API instead:
Store User Tokens
// Save tokens for a specific user function save_user_payment_tokens($user_id, $access_token, $refresh_token) { update_user_meta($user_id, 'user_payment_access_token', $access_token); update_user_meta($user_id, 'user_payment_refresh_token', $refresh_token); } // Call this for the current logged-in user // save_user_payment_tokens(get_current_user_id(), 'user_access_token', 'user_refresh_token');
Retrieve User Tokens
// Fetch tokens for a specific user function get_user_payment_tokens($user_id) { return array( 'access_token' => get_user_meta($user_id, 'user_payment_access_token', true), 'refresh_token' => get_user_meta($user_id, 'user_payment_refresh_token', true) ); }
Why Your Previous Attempt Failed
Mimicking WordPress registration code is tricky because that flow includes lots of extra validation, user role checks, and schema-specific logic that doesn't apply to storing simple tokens. The APIs above are purpose-built for storing arbitrary data safely, so they avoid those pitfalls.
Important Notes
- Security First: Tokens are sensitive—never print them to the front end or expose them in logs. Only use them in server-side code.
- Token Expiry: If your tokens expire, be sure to store the expiry timestamp along with them so you can automatically refresh tokens before they become invalid.
- Avoid Direct SQL: While you could use
$wpdbto write directly to a custom table, the Options/User Meta APIs handle SQL injection protection and data formatting for you, so they're always the safer choice.
Give these methods a shot—they should work smoothly without the hassle of reverse-engineering core WordPress code. Let me know if you hit any specific errors!
内容的提问来源于stack exchange,提问作者Ravi

