如何用requests库调用Bitchute POST搜索API?CSRF验证失败求助
解决Bitchute搜索接口CSRF验证失败的问题
问题背景
通过Firefox检查模式分析Bitchute网站请求,发现其搜索功能通过POST请求向https://www.bitchute.com/api/search/list/接口提交参数,返回包含搜索结果的JSON数据。尝试用requests库调用该接口时,出现CSRF验证失败的问题,原代码如下:
import requests # Set the search query and other parameters search_query = "12 monkeys" sort_by = "relevance" page = 0 # Set the URL and headers for the POST request url = "https://www.bitchute.com/api/search/list/" headers = { "Content-Type": "application/json", "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3", "Referer": "https://www.bitchute.com" } # Send a GET request to obtain the CSRF token response = requests.get("https://www.bitchute.com") csrf_token = response.cookies.get_dict().get("csrftoken") # Set the JSON payload for the POST request, including the CSRF token payload = { "query": search_query, "sort_by": sort_by, "page": page, "csrfmiddlewaretoken": csrf_token } # Send the POST request and get the response response = requests.post(url, headers=headers, data=payload) print(response)
问题分析
原代码存在3个核心问题导致CSRF验证失败:
- 错误设置
Content-Type为application/json,但接口实际接收表单格式数据 - 未在请求头中添加
X-CSRFToken字段(Django后端需同时验证Cookie与请求头中的CSRF Token) page参数类型不匹配,网站实际要求该参数为字符串而非整数
修正后的代码
import requests search_query = "12 monkeys" sort_by = "relevance" page = 0 url = "https://www.bitchute.com/api/search/list/" headers = { "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3", "Referer": "https://www.bitchute.com" } # 使用Session自动管理Cookie,避免手动传递 session = requests.Session() session.get("https://www.bitchute.com") csrf_token = session.cookies.get("csrftoken") # 构造表单格式的请求体,page参数转为字符串 payload = { "query": search_query, "sort_by": sort_by, "page": str(page), "csrfmiddlewaretoken": csrf_token } # 添加X-CSRFToken请求头,满足Django的CSRF验证要求 headers["X-CSRFToken"] = csrf_token # 发送POST请求,用data参数提交表单数据 response = session.post(url, headers=headers, data=payload) # 解析并输出结果 if response.status_code == 200: print(response.json()) else: print(f"请求失败,状态码: {response.status_code}") print(response.text)
关键注意事项
- 用
requests.Session()自动维护会话Cookie,确保CSRF Token在Cookie中持续有效 - 必须同时在请求头和表单参数中携带CSRF Token,二者缺一不可
- 严格匹配接口要求的参数类型(如
page需为字符串) - 不要手动设置
Content-Type,requests会自动根据data参数生成正确的表单类型头
内容的提问来源于stack exchange,提问作者Willem van Houten
相关产品推荐
相关产品推荐

