
本文介绍如何在 woocommerce rest api 中精准识别第三方客户端(通过 consumer_key),仅对该客户端的订单响应执行 clp→usd 货币转换,避免影响其他调用方。
本文介绍如何在 woocommerce rest api 中精准识别第三方客户端(通过 consumer_key),仅对该客户端的订单响应执行 clp→usd 货币转换,避免影响其他调用方。
WooCommerce REST API 默认对所有请求统一处理响应,但实际业务中常需为特定集成方(如某 ERP 或跨境支付平台)提供定制化数据格式。核心挑战在于:如何安全、可靠地识别当前请求来源,并仅对匹配的 API 客户端应用货币转换逻辑?
WooCommerce 的 REST 请求(v2/v3)在认证通过后,会将 OAuth 参数注入 $request 对象。其中 oauth_consumer_key 是唯一标识 API 密钥的关键字段。我们可通过该值查询数据库,确认请求是否来自目标客户端。
以下是完整、健壮的实现方案(兼容 WC 6.0+ 及 REST API v3):
✅ 步骤一:安全获取并验证 consumer_key
add_filter('woocommerce_rest_prepare_shop_order_object', 'filter_order_response_for_specific_client', 10, 3);
function filter_order_response_for_specific_client($response, $order, $request) {
// 仅处理已认证请求(跳过未授权或匿名访问)
if (!is_user_logged_in() && !isset($request->get_params()['oauth_consumer_key'])) {
return $response;
}
$consumer_key = $request->get_param('oauth_consumer_key');
// 必须存在且非空
if (!$consumer_key) {
return $response;
}
global $wpdb;
$table = $wpdb->prefix . 'woocommerce_api_keys';
// 使用 wc_api_hash() 安全比对(consumer_key 在 DB 中以哈希存储)
$hashed_key = wc_api_hash($consumer_key);
$user_id = (int) $wpdb->get_var(
$wpdb->prepare("SELECT user_id FROM {$table} WHERE consumer_key = %s AND permissions = 'read_write'", $hashed_key)
);
// ✅ 关键判断:仅当 user_id 匹配预设的「专属客户管理员 ID」时才启用转换
// 示例:假设该第三方客户端绑定到用户 ID 123(请替换为你的真实用户ID)
if ($user_id !== 123) {
return $response;
}
// ✅ 继续执行 CLP → USD 转换逻辑(仅限此客户端)
if ($response->data['currency'] === 'CLP') {
$exchange_rate = 812.0; // 建议从配置或缓存读取,避免硬编码
// 主订单字段
$response->data['currency'] = 'USD';
$response->data['total'] = round($response->data['total'] / $exchange_rate, 2);
$response->data['discount_total'] = round($response->data['discount_total'] / $exchange_rate, 2);
// 行项目(line_items)
foreach ($response->data['line_items'] as &$item) {
$item['total'] = round($item['total'] / $exchange_rate, 2);
$item['subtotal'] = round($item['subtotal'] / $exchange_rate, 2);
$item['price'] = round($item['price'] / $exchange_rate, 2);
}
unset($item); // 解除引用
// 优惠券(coupon_lines)
foreach ($response->data['coupon_lines'] as &$coupon) {
$coupon['discount'] = round($coupon['discount'] / $exchange_rate, 2);
}
unset($coupon);
// 退款(refunds)
foreach ($response->data['refunds'] as &$refund) {
$refund['total'] = round($refund['total'] / $exchange_rate, 2);
}
unset($refund);
}
return $response;
}
⚠️ 重要注意事项
- 安全性优先:consumer_key 本身不直接暴露用户身份,必须结合数据库查询 + wc_api_hash() 才能准确匹配。切勿使用 $_GET['oauth_consumer_key'] 等不安全方式。
- 权限校验:示例中增加了 permissions = 'read_write' 条件,确保只响应具备写权限的密钥(可根据需要调整为 'read')。
- 性能优化:频繁的数据库查询可能影响性能。生产环境建议使用 wp_cache_set/get 缓存 consumer_key → user_id 映射(缓存有效期建议 1 小时)。
- 汇率管理:硬编码汇率(如 812.0)不可维护。推荐接入实时汇率 API(如 exchangerate-api.com),或通过 WordPress 设置页面动态配置。
- 兼容性:本方案适用于 WooCommerce REST API v3(即 /wp-json/wc/v3/orders)。若需支持旧版 v2,请额外挂载 woocommerce_rest_prepare_shop_order_object(v2 使用相同钩子名,但参数顺序略有不同,建议统一升级至 v3)。
- 错误处理:未捕获数据库异常或无效汇率时,建议添加 try/catch 并记录日志(如 error_log()),避免因转换失败导致整个 API 响应中断。
✅ 验证与测试方法
- 在 WooCommerce → 设置 → API → REST API 中创建一个专属密钥,绑定给指定管理员用户(如 ID=123);
- 使用该密钥发起请求:
curl "https://yoursite.com/wp-json/wc/v3/orders/123" \ -u "ck_xxx:cs_xxx" \ -H "Content-Type: application/json"
- 检查响应中 currency 是否为 "USD",金额是否按预期换算;
- 用其他密钥请求同一订单,确认原始 CLP 数据保持不变。
通过此方案,你实现了精准、安全、可维护的客户端级响应定制——既满足第三方系统对接需求,又保障了平台整体 API 的稳定性与一致性。
大量免费API接口:立即使用
涵盖生活服务API、金融科技API、企业工商API、等相关的API接口服务。免费API接口可安全、合规地连接上下游,为数据API应用能力赋能!











