You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Invoke-WebRequest登录Liferay网页后会话无效求助

问题:使用Invoke-WebRequest登录Liferay网站后,Session无法保持登录状态

我尝试用PowerShell的Invoke-WebRequest自动登录某个基于Liferay的网站,登录请求返回302并获取到3个Cookie,但后续用该Session请求用户主页时,始终返回未登录的默认首页,状态码200。

登录代码

$urlLogin = "https://XXXXXX.es/web/XXXXX/inicio?p_p_id=com_liferay_login_web_portlet_LoginPortlet&p_p_lifecycle=1&p_p_state=normal&p_p_mode=view&_com_liferay_login_web_portlet_LoginPortlet_javax.portlet.action=%2Flogin%2Flogin&_com_liferay_login_web_portlet_LoginPortlet_mvcRenderCommandName=%2Flogin%2Flogin"

$loginPayload = @{
    _com_liferay_login_web_portlet_LoginPortlet_formDate                = "1692051569185"
    _com_liferay_login_web_portlet_LoginPortlet_saveLastPath            = $False
    _com_liferay_login_web_portlet_LoginPortlet_redirect                = ""
    _com_liferay_login_web_portlet_LoginPortlet_doActionAfterLogin      = $False
    _com_liferay_login_web_portlet_LoginPortlet_conexionInterna         = ""
    _com_liferay_login_web_portlet_LoginPortlet_masinformacionservicios = ""
    _com_liferay_login_web_portlet_LoginPortlet_login                   = $secrets.userbida
    _com_liferay_login_web_portlet_LoginPortlet_password                = $secrets.pwdbida
    p_auth                                                              = ""
}
$responseLogin = Invoke-WebRequest -Uri $urlLogin -Body $loginPayload -Method "POST" -SessionVariable session -MaximumRedirection 0 -SkipHttpErrorCheck -ErrorAction SilentlyContinue
if ($responseLogin.Headers.'Set-Cookie' -like '*JSESSIONID*') {
    Write-Host (get-date -format "dd-MM-yyyy HH:mm:ss") "INFO: Log In Succeded: $($responseLogin.Headers.'Set-Cookie'.Count) Cookies obtained`n$($responseLogin.Headers.'Set-Cookie')"
}
else {
    Write-Host (get-date -format "dd-MM-yyyy HH:mm:ss") "ERROR: Function $($MyInvocation.MyCommand) - Unable to get Cookies. Login Failed. Check parameters file or web status"
    throw
}

当前现象

  • 登录请求返回302状态码,获取到3个Cookie:
JSESSIONID=B39C532969F757DA32595072FE9C48E8.srvbidp089; Path=/; Secure; HttpOnly
COOKIE_SUPPORT=true; Max-Age=31536000; Expires=Wed, 14-Aug-2024 14:04:06 GMT; Path=/; Secure; HttpOnly
GUEST_LANGUAGE_ID=es_ES; Max-Age=31536000; Expires=Wed, 14-Aug-2024 14:04:06 GMT; Path=/; Secure; HttpOnly
  • 使用$session请求用户主页https://XXXX.es/group/XXX/inicio(GET请求)时,返回未登录状态的默认首页,状态码200。

补充信息

  • 执行流程:先提交登录数据到指定URL,禁用重定向获取Cookie;再用Session请求用户主页。
  • 该脚本在其他网站可正常运行,但此Liferay网站异常。
  • 浏览器登录时,登录请求返回302并附带10个额外Cookie,手动添加这些Cookie到Session变量也无法解决问题。

解决方案

针对Liferay网站的登录问题,调整以下几个关键点即可解决:

  1. 先获取登录页面的初始Cookie和p_auth令牌
    Liferay的登录请求需要有效的p_auth参数(当前代码设为空字符串,这是核心问题),该令牌由服务器在访问登录页面时生成,必须携带才能通过CSRF验证。
# 请求登录页面,获取初始Session和p_auth令牌
$loginPageUrl = "https://XXXXXX.es/web/XXXXX/inicio"
$loginPageResponse = Invoke-WebRequest -Uri $loginPageUrl -SessionVariable session

# 从页面HTML中提取p_auth值
$pAuth = [regex]::Match($loginPageResponse.Content, 'name="p_auth" value="([^"]+)"').Groups[1].Value
  1. 动态生成formDate并更新Payload
    formDate是当前时间戳,硬编码会失效,需实时生成;同时填写正确的跳转地址,帮助服务器完成登录后的状态同步:
$formDate = [DateTimeOffset]::Now.ToUnixTimeMilliseconds().ToString()
$loginPayload = @{
    _com_liferay_login_web_portlet_LoginPortlet_formDate                = $formDate
    _com_liferay_login_web_portlet_LoginPortlet_saveLastPath            = $False
    _com_liferay_login_web_portlet_LoginPortlet_redirect                = "/group/XXX/inicio" # 填写目标主页路径
    _com_liferay_login_web_portlet_LoginPortlet_doActionAfterLogin      = $False
    _com_liferay_login_web_portlet_LoginPortlet_conexionInterna         = ""
    _com_liferay_login_web_portlet_LoginPortlet_masinformacionservicios = ""
    _com_liferay_login_web_portlet_LoginPortlet_login                   = $secrets.userbida
    _com_liferay_login_web_portlet_LoginPortlet_password                = $secrets.pwdbida
    p_auth                                                              = $pAuth
}
  1. 允许重定向,让Session自动捕获完整Cookie
    禁用重定向会导致服务器后续生成的登录状态Cookie无法被Session捕获,去掉-MaximumRedirection 0参数,让Session自动处理重定向流程:
$responseLogin = Invoke-WebRequest -Uri $urlLogin -Body $loginPayload -Method "POST" -WebSession $session -ErrorAction Stop
  1. 验证登录状态
    请求用户主页后,通过页面特征判断是否登录成功:
$homePageResponse = Invoke-WebRequest -Uri "https://XXXX.es/group/XXX/inicio" -WebSession $session
if ($homePageResponse.Content -match "Bienvenido, $($secrets.userbida)") {
    Write-Host "登录成功,已进入用户主页"
} else {
    Write-Host "登录失败,仍未进入用户主页"
}

关键原因

Liferay依赖p_auth令牌防止CSRF攻击,且登录流程会经过多次重定向生成完整的登录Cookie集合。直接提交硬编码参数并禁用重定向,会导致Session缺少必要的验证信息,无法维持登录状态。


内容的提问来源于stack exchange,提问作者Daniziz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 16:03:18