You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Python Requests库提交表单请求登录Gamestop.ca遭遇403访问拒绝问题求助

Troubleshooting 403 Access Denied When Logging into GameStop.ca with Requests

Let’s break down why your requests script is hitting a 403 error while Selenium works perfectly—this almost always boils down to missing critical request details that a real browser (like Selenium mimics) automatically handles. Here’s how to fix it:

Key Issues with Your Current Script

Your code skips two essential steps that GameStop’s login system requires:

  1. No CSRF Token: Most modern sites use a CSRF (Cross-Site Request Forgery) token to validate form submissions. Directly sending a POST without this token triggers the 403.
  2. Missing Initial Session Setup: You need to first load the login page to capture cookies and the CSRF token, which your script doesn’t do.

Fixed Script with Critical Adjustments

First, install beautifulsoup4 (to parse the login page for the token) if you haven’t already:

pip install beautifulsoup4

Then use this updated code:

import requests
from bs4 import BeautifulSoup

# Mimic a real browser's request headers more closely
headers = {
    'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36',
    'Referer': 'https://www.gamestop.ca/Account/LogOn',
    'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9',
    'Accept-Language': 'en-US,en;q=0.9',
    'Accept-Encoding': 'gzip, deflate, br'
}

with requests.session() as s:
    # Step 1: Load the login page first to capture cookies and CSRF token
    login_page_response = s.get('https://www.gamestop.ca/Account/LogOn', headers=headers)
    soup = BeautifulSoup(login_page_response.content, 'html.parser')
    
    # Extract the CSRF token from the login form (check the input name in dev tools if this fails)
    csrf_token = soup.find('input', {'name': '__RequestVerificationToken'})['value']
    
    # Step 2: Build the payload with the CSRF token included
    payload = {
        'UserName': '*****',  # Replace with your actual username
        'Password': '******',  # Replace with your actual password
        'RememberMe': 'false',
        '__RequestVerificationToken': csrf_token
    }
    
    # Step 3: Send the POST request with all required data
    login_response = s.post('https://www.gamestop.ca/Account/LogOn', headers=headers, data=payload)
    
    print(login_response.status_code)
    print(login_response.text)

Additional Checks If You Still Get 403

  • Verify Form Field Names: Open GameStop’s login page in your browser, right-click → Inspect, and check the actual name attributes of the username/password inputs. They might differ from UserName/Password (e.g., Email instead of UserName).
  • Compare Requests with Selenium: Use your browser’s DevTools (Network tab) to capture the login request sent by Selenium. Compare its headers, form data, and cookies to what your requests script sends—adjust your script to match any missing details.
  • Check for Bot Detection: Even though Selenium works, GameStop might flag requests for missing subtle browser behaviors (like JavaScript rendering). If all else fails, you could use requests-html (which supports JS rendering) instead of plain requests.

内容的提问来源于stack exchange,提问作者whatsupbuttercup

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 22:17:34