2016-04-13 106 views
0

下面的PHP腳本是我們的REST API來獲取客戶信息作爲管理 -The腳本越來越管理員登錄並正確授權頁面,但在授權後,它給錯誤Magento的2.0 REST API OAuth錯誤

OAuthException對象([message:protected] =>無效的驗證/錯誤 請求(獲得403,期望的HTTP/1.1 20X或重定向) [string:Exception:private] => [code:protected] => 403 [ file:protected] => /home/xxxx/public_html/oauth_admin.php [line:protected] => 39 [trace:Exception:private] => Array([0] => Array([file] => /家用/ XXXXX /的public_html/oauth_admin.ph p [line] => 39 [function] => fetch [class] => OAuth [type] => - > [args] => Array([0] => http://www.xxxxx.com/api/rest/customers [1] => 2] => GET [3] => Array([Content-Type] => application/xml [Accept] => /)))) [previous:Exception:private] => [lastResponse] => { 「消息」:{「error」:[{「code」:403,「message」:「Access denied」}]}} [debugInfo] => Array([sbs] => xxxxx [body_recv] => { 「messages」:{「error」:[{「code」:403,「message」:「Access denied」}]}}))

我試過每個博客/在這個階段毫無疑問,這是非常明顯的事情,但我無法發現它......幫助我們非常感謝!

<?php 
$callbackUrl = "http://www.site2.com/oauth_admin.php"; 
$temporaryCredentialsRequestUrl = "http://www.site1.com/oauth/initiate?oauth_callback=" . urlencode($callbackUrl); 
$adminAuthorizationUrl = 'https://www.site1.com/admin/oauth_authorize'; 
$accessTokenRequestUrl = 'http://www.site1.com/oauth/token'; 
$apiUrl = 'http://www.site1.com/api/rest'; 
$consumerKey = 'xxxxx'; 
$consumerSecret = 'xxxxx'; 

session_start(); 
if (!isset($_GET['oauth_token']) && isset($_SESSION['state']) && $_SESSION['state'] == 1) { 
    $_SESSION['state'] = 0; 
} 
try { 
    $authType = ($_SESSION['state'] == 2) ? OAUTH_AUTH_TYPE_AUTHORIZATION : OAUTH_AUTH_TYPE_URI; 
    $oauthClient = new OAuth($consumerKey, $consumerSecret, OAUTH_SIG_METHOD_HMACSHA1, $authType); 
    $oauthClient->enableDebug(); 

    if (!isset($_GET['oauth_token']) && !$_SESSION['state']) { 
     $requestToken = $oauthClient->getRequestToken($temporaryCredentialsRequestUrl); 
     $_SESSION['secret'] = $requestToken['oauth_token_secret']; 
     $_SESSION['state'] = 1; 
     header('Location: ' . $adminAuthorizationUrl . '?oauth_token=' . $requestToken['oauth_token']); 
     exit; 
    } else if ($_SESSION['state'] == 1) { 
     $oauthClient->setToken($_GET['oauth_token'], $_SESSION['secret']); 
     $accessToken = $oauthClient->getAccessToken($accessTokenRequestUrl); 
     $_SESSION['state'] = 2; 
     $_SESSION['token'] = $accessToken['oauth_token']; 
     $_SESSION['secret'] = $accessToken['oauth_token_secret']; 
     header('Location: ' . $callbackUrl); 
     exit; 
    } else { 
     $oauthClient->setToken($_SESSION['token'], $_SESSION['secret']); 
     $resourceUrl = "$apiUrl/customers"; 
     //$oauthClient->fetch($resourceUrl); 
     $oauthClient->fetch($resourceUrl, array(), 'GET', array('Content-Type' => 'application/xml', 'Accept' => '*/*')); 
     $customers = json_decode($oauthClient->getLastResponse()); 
     print_r($customers); 

    } 
} catch (OAuthException $e) { 
    print_r($e); 
} 

回答

0

還不能評論,但用戶是否有正確的角色?有同樣的問題,它竟然是一個用戶,不允許訪問部分Magento。

下面就來的Magento這也解釋了這個文檔的鏈接:http://devdocs.magento.com/guides/m1x/api/rest/permission_settings/permission_settings.html

另外:進入系統>權限和檢查,如果你使用連接到API的用戶具有適當的權限。

+0

我一直在做更多的調試,似乎一切都工作正常的每個oauth步驟(驗證Postman休息客戶端)和每個管理員權限設置正確。日誌中顯示403錯誤,因爲**客戶端被服務器配置拒絕:/home/xxxxx/public_html/app/etc/local.xml** – Mikeysadleir

+0

這不是問題所在。它有時會發生。出於好奇:你爲什麼不使用這樣的東西[http://devdocs.magento.com/guides/m1x/api/soap/customer/customer.info.html] – JKMurray