| 开发者 | avalayer |
|---|---|
| 更新时间 | 2026年9月29日 11:51 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | MIT |
| 版权网址: | 版权信息 |
/wp-json/ava-pay/v1/verify-agent) that proxies signed agent requests to the AVA Pay API. Signatures are verified server-side against the agent platforms' published keys.unverifiable rather than as a rejection, and the storefront response says verification_unavailable instead of agent_blocked./wp-content/plugins/ava-pay-for-woocommerce/, or install through the WordPress plugins screen.https://…/wp-json/… URL. The settings page warns you if either is missing.Not for human shoppers: a page view without agent signature headers costs one check and nothing else. The verify endpoint is only exercised by agent traffic, and the storefront script loads only on page views that carry agent signature parameters. For a page view that does carry agent signature headers, the check runs after the page has been generated. On PHP-FPM and LiteSpeed hosts (most hosting) the response is finished first, so the agent is not kept waiting. On other server setups, such as Apache with mod_php, the page has been sent but the connection can stay open for up to about 2 seconds while the check completes. Only one check runs at a time for the whole site, checks are capped per agent and per site (see the question below), and you can turn them off in the settings.
Only agent requests are forwarded to the verification API: a request that reached the verify endpoint, and a page view that carried agent signature headers. For each, the plugin sends its method, its URL, its body if it has one (a page view has none), and the headers verification needs (the agent's signature headers, the headers that signature covers, and the protocol headers the verifier reads). Cookies, credentials, and other request headers are not forwarded. No customer, order, or session data is sent. See External services below for the full detail.
The verify endpoint is rate-limited per client IP (REMOTE_ADDR). If your host does not restore the real client IP, all traffic shares the proxy's IP and one rate-limit bucket. Preferably fix real-IP restoration at the server level (mod_remoteip / ngx_http_realip); alternatively, use the ava_pay_client_ip filter to supply the client IP from a header only your trusted proxy can set (e.g. CF-Connecting-IP when only Cloudflare can reach the origin).
Only for pages that are not served from the cache. A cached page is sent by your host or caching plugin without running WordPress or PHP, so the plugin never sees that visit and it is not shown under Agent visits. A cache that varies on, or bypasses for, the Signature header lets those visits through; most caches do neither by default.
Check these, in this order:
Up to 30 a minute and 2,000 a day for each agent, and up to 20 a minute and 2,000 a day for the whole site, one at a time. A visit is also skipped while another check is running, and an agent whose last check could not be completed (the verification service or the agent's key directory did not answer) is skipped for 10 minutes. Skipped visits are not listed; they are counted as "Not checked" under Agent visits, with the reason. Each check waits at most 2 seconds for the verification service. Developers can change the numbers with the ava_pay_page_visit_agent_per_minute, ava_pay_page_visit_agent_per_day, ava_pay_page_visit_site_per_minute, ava_pay_page_visit_site_per_day, ava_pay_page_visit_timeout and ava_pay_page_visit_backoff_seconds filters.
90 days. A daily scheduled task deletes older agent visit records (only those; verification and order records used for coupon attribution are not touched). Developers can change the period with the ava_pay_page_visit_retention_days filter. Deactivating or deleting the plugin removes the scheduled task.
No. Discounts are capped by your maximum, identity-only agents get 0% unless you explicitly raise the identity-only tier, and platform offers apply only to mandate-backed requests.
demo_agent on the Agent visits screen. The verify endpoint's answer to a demo request now includes "demo": true.source (whether a row came from the verify endpoint or a page visit; existing rows are marked as verify endpoint) and path (the page path, with the query string removed). No IP address, user agent or header values are stored.X-Forwarded-For and User-Agent unless the agent's signature covers them. Cookies and credentials are never sent, even when an agent's signature names them (such a request fails verification).unverifiable outcome and answers the storefront with verification_unavailable. Fail-closed behaviour is unchanged: such a request is still not admitted.