Call of Duty API在R语言中的身份认证问题及API调用咨询
Hey, let's break down why your current approach isn't working and fix it step by step.
The Core Issue
Your use of authenticate() with GET() is for HTTP Basic Authentication, but Call of Duty's login system uses form-based session authentication. When you log in via browser, the browser stores session cookies that are automatically sent with every subsequent request to prove you're authenticated. Your R code wasn't preserving this session state, hence the "Not permitted: not authenticated" error.
Step-by-Step Solution
To replicate the browser's session behavior in R, we'll use httr's session handle to manage cookies, first submit the login form to authenticate, then reuse that session for the API call.
Initialize a Session Handle
This creates a persistent session that automatically stores and sends cookies between requests:library(httr) library(jsonlite) library(rvest) # Needed to extract the CSRF token from the login page # Create a session handle tied to COD's domain cod_session <- handle("https://profile.callofduty.com")Submit the Login Form
COD's login requires a dynamic CSRF token (you can't just hardcode it). First fetch the login page to grab this token, then POST your credentials:# Fetch the login page to get the CSRF token login_page <- GET("https://profile.callofduty.com/cod/login", handle = cod_session) csrf_token <- login_page %>% read_html() %>% html_element('input[name="csrf"]') %>% html_attr("value") # Build the login form data login_payload <- list( username = "YOUR_COD_USERNAME", password = "YOUR_COD_PASSWORD", csrf = csrf_token, remember = "on" # Optional, keeps you logged in longer ) # Send the login request login_response <- POST( url = "https://profile.callofduty.com/do_login", handle = cod_session, body = login_payload, encode = "form" ) # Verify login success if (status_code(login_response) == 200) { message("Login successful!") } else { stop(paste("Login failed. Status code:", status_code(login_response))) }Request Player Data with Authenticated Session
Now use the samecod_sessionhandle to make your API call—this will automatically include the session cookies from the login:# Target API endpoint for savyultras90's Warzone data api_endpoint <- "https://my.callofduty.com/api/papi-client/stats/cod/v1/title/mw/platform/psn/gamer/savyultras90/profile/type/wz" api_response <- GET(api_endpoint, handle = cod_session) # Parse and use the JSON data if (status_code(api_response) == 200) { player_stats <- fromJSON(content(api_response, "text")) str(player_stats) # Preview the data structure } else { stop(paste("API request failed. Status code:", status_code(api_response))) }
Important Notes
- 2FA/Captchas: If your account has two-factor authentication enabled, or if COD triggers a captcha during login, this script will fail. In that case, you can log in via browser, export your session cookies, then load them into the
cod_sessionhandle manually. - API Changes: COD's API endpoints and authentication flow can change without warning. If this script stops working, use your browser's DevTools (F12) to inspect the actual login request and API calls to update the code.
- Cookie Expiry: Session cookies will eventually expire, so you'll need to re-run the login portion periodically.
内容的提问来源于stack exchange,提问作者A.B.

