如何避免Riot Games认证API返回'invalid_session_id'错误?
解决Riot Games认证API返回
invalid_session_id错误的方案 以下是针对问题的具体解决步骤:
1. 确保会话初始化请求被正确处理
你的代码中丢弃了第一个POST请求的响应,这会导致会话可能未正确建立。必须等待该请求完成并确认会话初始化成功,再执行后续的PUT登录请求。
2. 使用随机Nonce值
固定的nonce: "1"会触发会话验证失败,每次请求都应生成唯一的随机字符串作为Nonce。浏览器环境可以用crypto.randomUUID(),Node.js环境可以用uuid库生成。
3. 补充必要的请求头
Riot的API会校验User-Agent头,模拟浏览器UA可以避免被拦截。
4. 确保Cookie正确传递
- 浏览器环境下,
credentials: "include"是正确的,但要确保浏览器允许跨域Cookie(注意SameSite属性限制)。 - Node.js环境下,原生fetch不自动管理Cookie,需要使用
fetch-cookie配合tough-cookie来保存和传递会话Cookie。
修正后的浏览器环境代码示例
// 生成随机nonce const nonce = crypto.randomUUID(); // 初始化会话,确认响应状态 const initResponse = await fetch("https://auth.riotgames.com/api/v1/authorization", { method: "POST", credentials: "include", headers: { "Content-Type": "application/json", "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" }, body: JSON.stringify({ client_id: "play-valorant-web-prod", nonce: nonce, redirect_uri: "https://playvalorant.com/opt_in", response_type: "token id_token" }) }); if (!initResponse.ok) { throw new Error(`会话初始化失败: ${initResponse.status} ${initResponse.statusText}`); } // 执行登录请求 const loginResponse = await fetch("https://auth.riotgames.com/api/v1/authorization", { method: "PUT", credentials: "include", headers: { "Content-Type": "application/json", "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" }, body: JSON.stringify({ type: "auth", username: this._username, password: this._password }) }); const json = await loginResponse.json(); console.log(json);
Node.js环境Cookie管理示例
const fetch = require('node-fetch'); const { CookieJar } = require('tough-cookie'); const fetchCookie = require('fetch-cookie'); const { v4: uuidv4 } = require('uuid'); const cookieJar = new CookieJar(); const fetchWithCookie = fetchCookie(fetch, cookieJar); const nonce = uuidv4(); // 初始化会话 const initResponse = await fetchWithCookie("https://auth.riotgames.com/api/v1/authorization", { method: "POST", headers: { "Content-Type": "application/json", "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" }, body: JSON.stringify({ client_id: "play-valorant-web-prod", nonce: nonce, redirect_uri: "https://playvalorant.com/opt_in", response_type: "token id_token" }) }); if (!initResponse.ok) { throw new Error(`会话初始化失败: ${initResponse.status} ${initResponse.statusText}`); } // 执行登录请求 const loginResponse = await fetchWithCookie("https://auth.riotgames.com/api/v1/authorization", { method: "PUT", headers: { "Content-Type": "application/json", "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" }, body: JSON.stringify({ type: "auth", username: this._username, password: this._password }) }); const json = await loginResponse.json(); console.log(json);
注意:Riot Games的非公开API没有官方支持,使用这类API可能违反服务条款,存在账号被封禁的风险。
内容的提问来源于stack exchange,提问作者darkdarcool
相关产品推荐
相关产品推荐

