You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Puppeteer中自动绕过Cloudflare验证框与安全检测?

解决Puppeteer过Cloudflare验证的实用方案

核心结论

Node.js环境下完全可以实现自动通过Cloudflare的安全检测,你之前的问题大概率是因为指纹伪装不彻底、行为模拟不到位导致的。

具体调整方案

1. 优化依赖与指纹伪装配置

确保puppeteer-extra和stealth-plugin是最新版本,并且启用StealthPlugin的全部防护模块,覆盖更多浏览器指纹检测点:

npm update puppeteer-extra puppeteer-extra-plugin-stealth

修改代码里的StealthPlugin初始化:

puppeteer.use(StealthPlugin({
  enabledEvasions: [
    'chrome.runtime',
    'iframe.contentWindow',
    'navigator.hardwareConcurrency',
    'navigator.languages',
    'navigator.plugins',
    'navigator.vendor',
    'navigator.webdriver',
    'user-agent-override',
    'webgl.vendor',
    'window.outerdimensions'
  ]
}));

2. 规避Headless模式特征

即使你用了headless: false,Chrome还是会留下一些机器人特征,启动浏览器时添加以下参数:

const browser = await puppeteer.launch({ // 改用launch避免antibotbrowser的兼容问题
  headless: false,
  args: [
    '--disable-blink-features=AutomationControlled',
    '--disable-dev-shm-usage',
    '--no-sandbox',
    '--start-maximized', // 模拟真实窗口最大化
    '--disable-web-security',
    '--disable-features=VizDisplayCompositor'
  ]
});

3. 模拟真实用户行为

Cloudflare会检测页面加载后的行为,不要只靠waitForTimeout,添加鼠标移动、滚动等操作:

await page.goto("https://www.doordash.com", { waitUntil: 'networkidle2' });

// 模拟鼠标从左上角移动到验证框区域
await page.mouse.move(100, 100);
await page.mouse.move(300, 400);
// 模拟页面滚动
await page.evaluate(() => window.scrollBy(0, 200));

4. 自动处理Cloudflare勾选验证

针对普通的"I'm not a robot"勾选框,用更贴近真实用户的点击方式:

// 等待验证框出现
await page.waitForSelector('#cf-chl-widget', { timeout: 10000 });
// 找到勾选按钮并模拟真实点击
const checkbox = await page.$('#cf-chl-widget input[type="checkbox"]');
if (checkbox) {
  // 用mouse.click模拟真实点击,而非element.click
  const boxRect = await checkbox.boundingBox();
  await page.mouse.click(boxRect.x + boxRect.width/2, boxRect.y + boxRect.height/2);
  // 等待验证完成跳转
  await page.waitForNavigation({ waitUntil: 'networkidle2' });
}

5. 不要手动设置User-Agent

StealthPlugin会自动生成真实匹配的UA,手动设置反而可能因为UA与其他指纹不匹配被检测,删掉page.setUserAgent那行代码。

修改后的完整代码

import puppeteer from 'puppeteer-extra';
import StealthPlugin from 'puppeteer-extra-plugin-stealth';

// 启用StealthPlugin并配置全部防护
puppeteer.use(StealthPlugin({
  enabledEvasions: [
    'chrome.runtime',
    'iframe.contentWindow',
    'navigator.hardwareConcurrency',
    'navigator.languages',
    'navigator.plugins',
    'navigator.vendor',
    'navigator.webdriver',
    'user-agent-override',
    'webgl.vendor',
    'window.outerdimensions'
  ]
}));

(async () => {
  const browser = await puppeteer.launch({
    headless: false,
    args: [
      '--disable-blink-features=AutomationControlled',
      '--disable-dev-shm-usage',
      '--no-sandbox',
      '--start-maximized',
      '--disable-web-security',
      '--disable-features=VizDisplayCompositor'
    ]
  });

  const page = await browser.newPage();
  await page.setViewport({ width: 1366, height: 768 });

  await page.goto("https://www.doordash.com", { waitUntil: 'networkidle2' });

  // 模拟用户行为
  await page.mouse.move(100, 100);
  await page.mouse.move(300, 400);
  await page.evaluate(() => window.scrollBy(0, 200));

  // 处理Cloudflare验证
  try {
    await page.waitForSelector('#cf-chl-widget', { timeout: 10000 });
    const checkbox = await page.$('#cf-chl-widget input[type="checkbox"]');
    if (checkbox) {
      const boxRect = await checkbox.boundingBox();
      await page.mouse.click(boxRect.x + boxRect.width/2, boxRect.y + boxRect.height/2);
      await page.waitForNavigation({ waitUntil: 'networkidle2', timeout: 20000 });
    }
  } catch (err) {
    console.log("未检测到Cloudflare验证框,或验证超时");
  }

  const title = await page.title();
  console.log("Page title:", title);
  await browser.close();
})();

注意事项

  • 如果遇到hCaptcha或更复杂的验证,自动过检难度会大幅提升,这种情况可能需要结合第三方打码服务。
  • Cloudflare的检测规则会不断更新,上述方案可能需要定期调整依赖和配置。

内容的提问来源于stack exchange,提问作者wdwd

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 05:16:04