使用Python、BeautifulSoup4和Mechanize实现网站登录时状态码始终返回200求助
Hey there, I see you're stuck on figuring out if your login succeeded since you always get a 200 status code—even when using wrong passwords. Let's break down why this happens and fix it step by step.
First, Understand the Root Cause
Most modern web apps return a 200 status code even on login failure (they just reload the login page with an error message) instead of throwing a 4xx/5xx error. So checking the status code alone won't tell you if login worked. You need to analyze the response content or post-login URL instead.
Step-by-Step Fixes & Improvements
1. Make Form Selection & Field Names More Reliable
Your code uses br.select_form(nr=0) to pick the login form, but this is fragile—if the page has other forms (like a search bar), you might be selecting the wrong one. Here's how to fix this:
- Use the form's
nameattribute (check the login page's HTML source for<form name="loginForm">or similar) for consistent selection. - Print out the form's fields to confirm you're using the correct
namevalues for username/password (notidor placeholder text!).
Example code adjustment:
# Try selecting form by name first (replace with your actual form name) try: br.select_form(name='loginForm') except mechanize.FormNotFoundError: print("Falling back to form index 0...") br.select_form(nr=0) # Print all form fields to verify their names print("Available form fields:", [ctrl.name for ctrl in br.form.controls if ctrl.name])
2. Analyze Response Content for Success/Failure Cues
After submitting the form, parse the page with BeautifulSoup to look for specific indicators that tell you if login worked:
- A welcome message (e.g., "Welcome, [Your Username]")
- A dashboard element that only appears post-login
- An error message (e.g., "Invalid username or password")
Add this code right after br.submit():
mainpage_content = br.response().read() soup = BeautifulSoup(mainpage_content, 'html.parser') # Check for success indicators (customize these to match your app) success_indicators = soup.find(text=lambda t: t and 'Dashboard' in t) or soup.find(id='welcome-user') if success_indicators: print("✅ Login successful!") else: # Check for error messages error_box = soup.find(class_='error-alert') # Replace with your app's error class/id if error_box: print(f"❌ Login failed: {error_box.text.strip()}") else: # Fallback: Check if we're still on the login page if br.geturl() == LOGIN_URL: print("❌ Login failed: Still on login page") else: print("✅ Login successful (redirected to new page)!")
3. Fix Common Configuration Gaps
- Add HTTP/HTTPS to your LOGIN_URL: Your current
LOGIN_URL = 'www.xyz.com/login.aspx'is missing the protocol—Mechanize needshttps://www.xyz.com/login.aspxto connect correctly. - Use a realistic User-Agent: Your current
'Chrome'is too simplistic. Swap it for a full browser user-agent string to avoid being flagged as a crawler:br.addheaders = [('User-agent', 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36')] - Handle ASP.NET Hidden Fields: If your app uses ASP.NET, it might include
__VIEWSTATEor__EVENTVALIDATIONhidden fields. Mechanize usually handles these automatically, but if you run into issues, try this:br.select_form(nr=0) br.form.set_all_readonly(False) # Ensure hidden fields are editable if needed
4. Implement Logout Logic
Once you confirm login works, add code to logout by finding the logout link/button:
try: # Follow the logout link by text (customize to match your app) br.follow_link(text='Logout') print("🔒 Logged out successfully") except mechanize.LinkNotFoundError: # Alternatively, submit the logout form if needed br.select_form(name='logoutForm') br.submit()
Additional Troubleshooting Tips
- Manually login to your app while using Chrome DevTools (F12) to inspect the network request: Check the form's action URL, method (POST/GET), and all submitted fields to ensure your code matches.
- Print the full
mainpage_contentafter login to see exactly what the server is returning—this will help you identify the right success/failure cues.
内容的提问来源于stack exchange,提问作者Devesh Tiwari

