如何在roblox.com页面发送带认证的economy.roblox.com API请求?
解决Roblox跨子域API请求认证问题
方案1:配置Fetch请求的Credentials选项
先确认你的fetch请求是否正确携带跨域凭证。roblox.com和economy.roblox.com属于同根域的子域名,ROBLOSECURITY Cookie的Domain通常设置为.roblox.com,只需在请求中添加credentials: 'include',浏览器就会自动携带Cookie:
fetch('https://economy.roblox.com/v1/user/currency', { method: 'GET', credentials: 'include' // 关键:携带跨域凭证 }) .then(response => response.json()) .then(data => { console.log('Robux数量:', data.robux); // 在此处理获取到的数据,无需跳转页面 }) .catch(err => console.error('请求失败:', err));
如果该方法无效,说明Roblox的CORS策略限制了roblox.com对economy.roblox.com的直接请求,可尝试iframe方案。
方案2:通过隐藏iframe发起请求并传递数据
利用隐藏iframe加载economy.roblox.com页面,在iframe内执行API请求,再通过postMessage将结果传回主页面:
步骤1:创建隐藏iframe并注入脚本
// 创建隐藏iframe const iframe = document.createElement('iframe'); iframe.style.display = 'none'; iframe.src = 'https://economy.roblox.com/'; // 加载economy子域页面,确保Cookie可用 // 监听iframe加载完成事件 iframe.onload = function() { // 向iframe注入请求脚本 const script = iframe.contentDocument.createElement('script'); script.textContent = ` fetch('https://economy.roblox.com/v1/user/currency', { credentials: 'include' }) .then(res => res.json()) .then(data => { // 向主页面发送数据 window.parent.postMessage({ type: 'ROBUX_DATA', data: data }, 'https://www.roblox.com'); }) .catch(err => { window.parent.postMessage({ type: 'ROBUX_ERROR', error: err.message }, 'https://www.roblox.com'); }); `; iframe.contentDocument.body.appendChild(script); }; // 添加iframe到页面 document.body.appendChild(iframe); // 监听来自iframe的消息 window.addEventListener('message', function(event) { // 验证消息来源,确保安全 if (event.origin !== 'https://economy.roblox.com') return; if (event.data.type === 'ROBUX_DATA') { console.log('获取到Robux:', event.data.data.robux); // 在此处理数据,比如更新页面内容 document.body.removeChild(iframe); // 完成后移除iframe } else if (event.data.type === 'ROBUX_ERROR') { console.error('请求出错:', event.data.error); document.body.removeChild(iframe); } });
注意事项
postMessage的目标Origin需设置为主页面域名(https://www.roblox.com),避免接收恶意消息。- 必须等iframe加载完成后再注入脚本,确保环境已初始化并携带正确Cookie。
方案3:使用浏览器扩展(若允许)
如果是在自己的浏览器环境中操作,可编写简单的浏览器扩展,扩展拥有跨域请求权限,不受页面CORS限制:
// 扩展background脚本 chrome.runtime.onMessage.addListener((request, sender, sendResponse) => { if (request.action === 'getRobux') { fetch('https://economy.roblox.com/v1/user/currency', { credentials: 'include' }) .then(res => res.json()) .then(data => sendResponse(data)) .catch(err => sendResponse({ error: err.message })); return true; // 保持端口开放,异步返回结果 } }); // 页面注入脚本 chrome.runtime.sendMessage({ action: 'getRobux' }, (response) => { if (response.error) { console.error('请求失败:', response.error); } else { console.log('Robux数量:', response.robux); } });
该方案适合长期使用,需自行打包并安装扩展。
内容的提问来源于stack exchange,提问作者0x64
相关产品推荐
相关产品推荐

