HISE Logo Forum
    • Categories
    • Register
    • Login

    Get data from Woocommerce via server api

    Scheduled Pinned Locked Moved Scripting
    authenticationserverapiwoocommerce
    109 Posts 11 Posters 9.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • orangeO
      orange @d.healey
      last edited by

      @d-healey said in Get data from Woocommerce via server api:

      Probably no harm in generating one for each request, unless you think the user is going to be making lots of requests. I'll probably store mine in a file that will expire each day.

      Which method can be used for each day expiration?

      develop Branch / XCode 13.1
      macOS Monterey / M1 Max

      d.healeyD 1 Reply Last reply Reply Quote 0
      • d.healeyD
        d.healey @orange
        last edited by

        @orange You can add a timestamp inside your encrypted file and compare it to the current time when you read the file.

        Libre Wave - Freedom respecting instruments and effects
        My Patreon - HISE tutorials
        YouTube Channel - Public HISE tutorials

        1 Reply Last reply Reply Quote 1
        • d.healeyD
          d.healey
          last edited by

          Ooo fancy stuff in the latest commit...

          downloads are persistent when recompiling

          What does this mean?

          Libre Wave - Freedom respecting instruments and effects
          My Patreon - HISE tutorials
          YouTube Channel - Public HISE tutorials

          1 Reply Last reply Reply Quote 0
          • Christoph HartC
            Christoph Hart
            last edited by

            The Server class was owned by the scripting engine so when you recompile it will create a new server class and all downloads are gone. This was bad and now the server class has the same lifetime as the plugin itself.

            d.healeyD 2 Replies Last reply Reply Quote 2
            • d.healeyD
              d.healey @Christoph Hart
              last edited by

              @Christoph-Hart Excellent!

              Libre Wave - Freedom respecting instruments and effects
              My Patreon - HISE tutorials
              YouTube Channel - Public HISE tutorials

              1 Reply Last reply Reply Quote 0
              • d.healeyD
                d.healey @Christoph Hart
                last edited by d.healey

                @Christoph-Hart Compile errors unfortunately

                ../../../../../HISE/hi_components/floating_layout/FloatingTileFactoryMethods.cpp:358:43: error: ‘web’ is not a member of ‘MainToolbarIcons’
                   path.loadPathFromData(MainToolbarIcons::web, sizeof(MainToolbarIcons::web));
                                                           ^~~
                ../../../../../HISE/hi_components/floating_layout/FloatingTileFactoryMethods.cpp:358:73: error: ‘web’ is not a member of ‘MainToolbarIcons’
                   path.loadPathFromData(MainToolbarIcons::web, sizeof(MainToolbarIcons::web));
                

                Libre Wave - Freedom respecting instruments and effects
                My Patreon - HISE tutorials
                YouTube Channel - Public HISE tutorials

                1 Reply Last reply Reply Quote 0
                • Christoph HartC
                  Christoph Hart
                  last edited by

                  Ah yes I forgot to commit this file. You can just comment these lines out, it shouldn't affect anything.

                  d.healeyD 1 Reply Last reply Reply Quote 1
                  • d.healeyD
                    d.healey @Christoph Hart
                    last edited by

                    @Christoph-Hart Yep that worked. This server controller looks useful. Going to play around with it now.

                    Libre Wave - Freedom respecting instruments and effects
                    My Patreon - HISE tutorials
                    YouTube Channel - Public HISE tutorials

                    1 Reply Last reply Reply Quote 0
                    • d.healeyD
                      d.healey
                      last edited by d.healey

                      @orange Have you had any luck getting user order data through JWT authorization? WooCommerce seems to block any user that isn't an admin.

                      I think we may be forced to use the consumer/secret key thingy!

                      Libre Wave - Freedom respecting instruments and effects
                      My Patreon - HISE tutorials
                      YouTube Channel - Public HISE tutorials

                      orangeO 1 Reply Last reply Reply Quote 0
                      • orangeO
                        orange @d.healey
                        last edited by orange

                        @d-healey said in Get data from Woocommerce via server api:

                        @orange Have you had any luck getting user order data through JWT authorization? WooCommerce seems to block any user that isn't an admin.

                        Not yet, I tried lot's of thing but interestingly my server doesn't allow http header auth...

                        I think we may be forced to use the consumer/secret key thingy!

                        Yes it seems like that then. By the way don't forget to delete Server.setHttpHeader, because in this case woocommerce is blocking.

                        develop Branch / XCode 13.1
                        macOS Monterey / M1 Max

                        d.healeyD 1 Reply Last reply Reply Quote 0
                        • d.healeyD
                          d.healey @orange
                          last edited by d.healey

                          @orange So how do we do it securely? Embedding keys in the binary seems risky. I'm also going to see if making custom endpoints will work.

                          Libre Wave - Freedom respecting instruments and effects
                          My Patreon - HISE tutorials
                          YouTube Channel - Public HISE tutorials

                          orangeO 1 Reply Last reply Reply Quote 0
                          • orangeO
                            orange @d.healey
                            last edited by orange

                            @d-healey said in Get data from Woocommerce via server api:

                            @orange So how do we do it securely? Embedding keys in the binary seems risky. I'm also going to see if making custom endpoints will work.

                            If you won't create customers, create orders...etc with Woocommece API, you can give Read only permissions to the keys. So the keys can only be used for getting data. yes it is risky too but at least not on the website compromise level.

                            develop Branch / XCode 13.1
                            macOS Monterey / M1 Max

                            1 Reply Last reply Reply Quote 1
                            • orangeO
                              orange
                              last edited by orange

                              I guess Application Passwords Plugin is the alternative to JWT Authentication Plugin. Some people says it is much more easy to use, maybe this method won't be blocked.

                              develop Branch / XCode 13.1
                              macOS Monterey / M1 Max

                              1 Reply Last reply Reply Quote 1
                              • orangeO
                                orange
                                last edited by orange

                                By the way, you didn't try to get data with JWT header auth from Woocommerce REST API right?
                                JWT can be used for Wordpress REST API only.
                                And since every customer is a user at the same time, I think with Wordpress API you should get the user (customer) data.

                                develop Branch / XCode 13.1
                                macOS Monterey / M1 Max

                                d.healeyD 1 Reply Last reply Reply Quote 0
                                • d.healeyD
                                  d.healey @orange
                                  last edited by

                                  @orange I tried with both WooCommerce and Wordpress. JWT can be used with WooCommerce endpoints, but they block every user without admin rights. I can't see a way to get customer order details from the Wordpress API.

                                  Libre Wave - Freedom respecting instruments and effects
                                  My Patreon - HISE tutorials
                                  YouTube Channel - Public HISE tutorials

                                  1 Reply Last reply Reply Quote 0
                                  • Christoph HartC
                                    Christoph Hart
                                    last edited by

                                    Have you tried this:

                                    Link Preview Image
                                    JWT on Woocommerce cannot work with "Customer" role user

                                    I developing mobile apps, that connect directly to woocommerce rest api. I use this plugin for authenticating, like registering, login, make an order, etc. So the issue come, when I register new u...

                                    favicon

                                    WordPress Development Stack Exchange (wordpress.stackexchange.com)

                                    d.healeyD 1 Reply Last reply Reply Quote 1
                                    • d.healeyD
                                      d.healey @Christoph Hart
                                      last edited by d.healey

                                      Sorry Christoph, somehow I missed your reply. Giving extra priviliages to the user didn't work for me, and seems like a hack anyway.

                                      @orange I have found the solution, make your own API with custom endpoints. It's actually not too difficult, I found some good information on the wordpress website and YouTube.

                                      Here is a custom plugin I just made that will get all of the downloadable file data for all of the customer's completed orders. It checks that the current user (via JWT for example) has the role of customer, I'll add more security later to make sure they have permission to download specific files etc. This is just a proof of concept and doesn't take arguments from HISE server calls yet.

                                      <?php
                                      /**
                                       * Plugin Name: Custom API
                                       * Plugin URI: http://localhost/wordpress
                                       * Description: Custom REST API endpoints
                                       * Version: 1.0
                                       * Author: David Healey
                                      */
                                      
                                      function my_orders() {
                                      
                                      	$args = [
                                      		'status' => 'wc-completed',
                                      		'customer' => 'customer@example.com'
                                      	];
                                      
                                      	$orders = wc_get_orders($args);
                                      
                                      	$data = [];
                                      
                                      	foreach ($orders as $i => $order) {
                                      	
                                      		$items = $order->get_items();
                                      				
                                      		$data[$i] = [];
                                      		
                                      		foreach($items as $j => $item) {
                                      			$data[$i][$j] = $item->get_item_downloads();
                                      		}
                                      	}
                                      
                                      	return $data;
                                      }
                                      
                                      add_action('rest_api_init', function() {
                                      	register_rest_route('my/v1', 'orders', [
                                              'methods' => 'GET',
                                      		'callback' => 'my_orders',
                                          	'permission_callback' => function () {
                                      		     return wc_current_user_has_role( 'customer' );
                                          	}
                                          ]);
                                      });	
                                      

                                      The API documentation was tricky to find, every Google search lead to the REST API instead of the plugin API. If you need it here it is - https://developer.woocommerce.com/

                                      Libre Wave - Freedom respecting instruments and effects
                                      My Patreon - HISE tutorials
                                      YouTube Channel - Public HISE tutorials

                                      orangeO Dan KorneffD 2 Replies Last reply Reply Quote 1
                                      • orangeO
                                        orange @d.healey
                                        last edited by

                                        @d-healey Thank you for the info. I'll check that out!

                                        develop Branch / XCode 13.1
                                        macOS Monterey / M1 Max

                                        1 Reply Last reply Reply Quote 0
                                        • orangeO
                                          orange
                                          last edited by orange

                                          I was struggling with HTTP JWT token authentication for API requests. I edited .htaccess and wp-config files. Taking tokens was fine but http header authentication still was not working.

                                          I've found the real cause that is Wordfence Security plugin for Wordpress. The Firewall was blocking the API requests.

                                          So, I disabled Prevent discovery of usernames through '/?author=N' scans, the oEmbed API, the WordPress REST API, and WordPress XML Sitemaps option in Firewall Options of Wordfence, and then the issue is solved.

                                          develop Branch / XCode 13.1
                                          macOS Monterey / M1 Max

                                          d.healeyD 1 Reply Last reply Reply Quote 1
                                          • d.healeyD
                                            d.healey @orange
                                            last edited by

                                            @orange Are you using a real server or are you using an offline test server like xampp?

                                            Libre Wave - Freedom respecting instruments and effects
                                            My Patreon - HISE tutorials
                                            YouTube Channel - Public HISE tutorials

                                            orangeO 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post

                                            31

                                            Online

                                            1.7k

                                            Users

                                            11.8k

                                            Topics

                                            102.5k

                                            Posts