You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python发送application/x-www-form-urlencoded POST请求遇配置错误求助

问题:Python发送application/x-www-form-urlencoded POST请求失败

尝试发送application/x-www-form-urlencoded类型的POST请求时遇到两个问题:

  • 将book_token以字符串形式传入时返回500(Internal Server Error)
  • 以字典形式传入时触发错误:
    "/Library/Developer/CommandLineTools/Library/Frameworks/Python3.framework/Versions/3.9/lib/python3.9/http/client.py", line 1049, in _send_output
      chunk = f'{len(chunk):X}\r\n'.encode('ascii') + chunk
    TypeError: can't concat str to bytes
    

该请求在POSTMAN和Burp Suite中可正常执行,但用Python的requests库和http.client都无法成功。以下是代码和Burp请求示例:

Python代码

# Request: Book Reservation
conn = http.client.HTTPSConnection("api.resy.com")

payload = f"book_token={urllib.parse.quote_plus(book_token)}&struct_payment_method={urllib.parse.quote_plus(struct_payment)}&source_id=resy.com-venue-details"

headers = {
    'Content-Type': 'application/x-www-form-urlencoded',
    'X-Resy-Auth-Token': x_resy_token,
    'Authorization': auth_token,
    'X-Resy-Universal-Auth': x_resy_token,
  }
conn.request("POST", "/3/book", payload, headers)
res = conn.getresponse()
data = res.read()
print(data.decode("utf-8"))

Burp Suite请求示例

POST /3/book HTTP/2
Host: api.resy.com
Content-Length: 871
Sec-Ch-Ua: 
X-Origin: https://widgets.resy.com
Sec-Ch-Ua-Mobile: ?0
X-Resy-Auth-Token: <MY_TOKEN>
Authorization: <MY_TOKEN>
User-Agent: <STUFF>
Chrome/115.0.5790.110 Safari/537.36
X-Resy-Universal-Auth: <MY_TOKEN>
Content-Type: application/x-www-form-urlencoded
Accept: application/json, text/plain, */*
Cache-Control: no-cache
Sec-Ch-Ua-Platform: ""
Origin: https://widgets.resy.com
Sec-Fetch-Site: same-site
Sec-Fetch-Mode: cors
Sec-Fetch-Dest: empty
Referer: https://widgets.resy.com/
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9

book_token=<TOKEN>&struct_payment_method=<MY_TOKEN>&source_id=resy.com-venue-details

解决方案

1. 修复http.client的字节拼接错误

http.client.request的body参数需传入字节类型,直接传字符串会触发拼接错误,修改代码如下:

payload = f"book_token={urllib.parse.quote_plus(book_token)}&struct_payment_method={urllib.parse.quote_plus(struct_payment)}&source_id=resy.com-venue-details"
# 将字符串编码为utf-8字节
payload_bytes = payload.encode('utf-8')
conn.request("POST", "/3/book", payload_bytes, headers)

2. 补全缺失的关键请求头

对比Burp请求,你的代码缺少多个服务器验证必需的请求头,补全后再测试:

headers = {
    'Content-Type': 'application/x-www-form-urlencoded',
    'X-Resy-Auth-Token': x_resy_token,
    'Authorization': auth_token,
    'X-Resy-Universal-Auth': x_resy_token,
    'X-Origin': 'https://widgets.resy.com',
    'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.5790.110 Safari/537.36',
    'Accept': 'application/json, text/plain, */*',
    'Cache-Control': 'no-cache',
    'Origin': 'https://widgets.resy.com',
    'Sec-Fetch-Site': 'same-site',
    'Sec-Fetch-Mode': 'cors',
    'Sec-Fetch-Dest': 'empty',
    'Referer': 'https://widgets.resy.com/',
    'Accept-Encoding': 'gzip, deflate',
    'Accept-Language': 'en-US,en;q=0.9'
}

3. 改用requests库简化请求

requests会自动处理表单编码和字节转换,比http.client更易用,示例代码:

import requests

url = "https://api.resy.com/3/book"
payload = {
    'book_token': book_token,
    'struct_payment_method': struct_payment,
    'source_id': 'resy.com-venue-details'
}
headers = {
    # 填入补全后的所有请求头
    'X-Resy-Auth-Token': x_resy_token,
    'Authorization': auth_token,
    'X-Resy-Universal-Auth': x_resy_token,
    'X-Origin': 'https://widgets.resy.com',
    'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.5790.110 Safari/537.36',
    'Accept': 'application/json, text/plain, */*',
    'Cache-Control': 'no-cache',
    'Origin': 'https://widgets.resy.com',
    'Referer': 'https://widgets.resy.com/'
}

# 使用data参数自动处理application/x-www-form-urlencoded格式
response = requests.post(url, data=payload, headers=headers)
print(response.text)

4. 验证请求体一致性

打印生成的请求体,对比Burp中的原始内容,确保book_token、struct_payment_method的编码和内容完全一致,避免因编码遗漏导致服务器报错。

内容的提问来源于stack exchange,提问作者philip.a20

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 14:47:51