You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Python Requests登录mediamarkt.pl遭遇403错误,请求技术协助

问题:登录mediamarkt.pl时遭遇403错误

尝试为https://mediamarkt.pl开发登录功能,始终返回403错误,已添加请求头但问题未解决,实现代码如下:

import requests


s = requests.Session()

user_agent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"

headers = {

    'Authority':'mediamarkt.pl',
    'Method':'POST',
    'Path': '/api/v1/msg',
    'User-Agent': user_agent,
    'Content-Type': 'application/json',
    'Referer': 'https://mediamarkt.pl/pl/myaccount/auth/login?redirectURL=%2F',
}


def login_site(email, password):

    login_url = 'https://mediamarkt.pl/api/v1/msg'
    form_data = {
        'email': email,
        'password': password,
        'mms-login-form__login-button':'Zaloguj się',
        }
    login = s.post(login_url, data=form_data, headers=headers)

    if login.status_code == 200:
        print("Login successful!")
        print("Server response:")
        print(login.text)
    else:
        print(f"Login error. Response status: {login.status_code}")


email = "XYZ@gmail.com"

password = "XYZ123!"

login_site(email, password)

恳请协助排查403错误原因并提供解决方案。


排查与解决方案

核心错误点分析

  • 请求头冗余且矛盾:手动设置Method、Authority、Path完全多余,requests会自动处理这些字段;同时你设置了Content-Type: application/json,但用data参数发送的是表单格式数据,格式不匹配会触发服务器拦截。
  • 接口路径错误:/api/v1/msg大概率不是真实的登录接口,真实登录接口需要通过浏览器抓包确认(比如访问登录页面后,点击登录按钮时的请求URL)。
  • 缺少验证参数:多数网站登录要求携带CSRF令牌,你没有先访问登录页面获取必要的Cookie和CSRF值,直接提交请求会被判定为非法请求。
  • 不必要的表单字段:mms-login-form__login-button这类按钮字段通常是前端表单的冗余数据,服务器不会接收该参数,反而可能引发校验问题。

修正后的实现步骤

  1. 先访问登录页面获取Cookie和CSRF令牌:通过Session访问登录页面,自动保存Cookie,并从页面源码或响应头中提取CSRF值(具体位置需要抓包确认,比如页面中的meta标签或响应Cookie)。
  2. 修正请求头:移除冗余字段,根据真实请求的Content-Type设置正确值(如果是表单提交则用application/x-www-form-urlencoded,如果是JSON则用application/json)。
  3. 使用正确的登录接口:通过浏览器开发者工具(F12)抓包,找到点击登录时实际发送请求的URL和参数格式。
  4. 提交正确的参数:只保留服务器需要的参数(如email、password、csrf_token等)。

示例代码(基于常见场景调整)

import requests
from bs4 import BeautifulSoup

s = requests.Session()
user_agent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
headers = {
    'User-Agent': user_agent,
    'Referer': 'https://mediamarkt.pl/pl/myaccount/auth/login?redirectURL=%2F'
}

def login_site(email, password):
    # 第一步:访问登录页面,获取Cookie和CSRF令牌
    login_page_url = 'https://mediamarkt.pl/pl/myaccount/auth/login?redirectURL=%2F'
    response = s.get(login_page_url, headers=headers)
    soup = BeautifulSoup(response.text, 'html.parser')
    # 假设CSRF令牌在meta标签中,实际需要根据页面结构调整
    csrf_token = soup.find('meta', attrs={'name': 'csrf-token'})['content']

    # 第二步:确认真实登录接口(这里需要替换为抓包得到的URL)
    real_login_url = 'https://mediamarkt.pl/api/v1/auth/login'
    # 构造正确的请求参数(根据抓包结果调整)
    login_data = {
        'email': email,
        'password': password,
        '_csrf': csrf_token
    }
    # 修正Content-Type为表单提交格式
    login_headers = headers.copy()
    login_headers['Content-Type'] = 'application/x-www-form-urlencoded'

    # 第三步:发送登录请求
    login_response = s.post(real_login_url, data=login_data, headers=login_headers)

    if login_response.status_code == 200:
        print("Login successful!")
        print("Server response:")
        print(login_response.text)
    else:
        print(f"Login error. Response status: {login_response.status_code}")
        print("Response content:")
        print(login_response.text)

email = "XYZ@gmail.com"
password = "XYZ123!"
login_site(email, password)

额外注意事项

  • 部分网站会检测请求的频率、指纹(如浏览器特征),如果仍出现403,可尝试添加更多真实浏览器的请求头(如Accept、Accept-Language等)。
  • 确保使用的Session对象全程复用,保持Cookie一致性。

内容的提问来源于stack exchange,提问作者匿名

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 09:27:24