如何用Python requests登录指定网站?解决Invalid CSRF token报错问题
Hey there, let's break down why you're hitting that 403 error with the CSRF token issue and get your login working smoothly. Here's what's going wrong and how to fix it:
What's Causing the Problem?
Most modern websites don’t store CSRF tokens directly in cookies anymore—they embed these tokens in the login page’s HTML (usually as a meta tag or hidden form field). Your current code only fetches the login page but never extracts this critical token, so when you send the POST request, the server rejects it with a 403 because it doesn’t see a valid token. On top of that, you’re mixing direct requests.get()/requests.post() calls instead of using your session object, which means you’re not preserving the session cookies the server sets to track your session.
Step-by-Step Fix
- Stick to one Session instance for all requests to keep cookies consistent.
- Extract the CSRF token from the login page’s HTML (we’ll use BeautifulSoup for easy parsing).
- Include the token in your POST data when submitting the login form.
Corrected Code
First, install BeautifulSoup if you haven’t already:
pip install beautifulsoup4
Then use this revised code:
import requests as r from bs4 import BeautifulSoup # Initialize a session to persist cookies across requests session = r.Session() # Fetch the login page to get the CSRF token and session cookies login_url = "https://partner.getyourguide.com/en-us/login" login_page = session.get(login_url) login_page.raise_for_status() # Crash immediately if the page fails to load # Parse the HTML to find the CSRF token soup = BeautifulSoup(login_page.text, "html.parser") # Look for the CSRF token in a meta tag (a common pattern) csrf_token = soup.find("meta", attrs={"name": "csrf-token"})["content"] # If the meta tag doesn't work, check for a hidden form field instead: # csrf_token = soup.find("input", attrs={"name": "_csrf"})["value"] # (Use your browser's F12 tools to inspect the login form and confirm the exact field name) # Prepare login data with the CSRF token included login_data = { "email": "hello@world.com", "password": "password", # Fixed your typo here! "_csrf": csrf_token # Match the field name from the login form } # Submit the login request using the same session response = session.post(login_url, data=login_data) # Check the result print(f"Response Status: {response.status_code}") if response.status_code == 200: print("Login successful!") else: # Print a snippet of the response to debug if needed print(f"Login failed. Response preview: {response.text[:500]}")
Key Tips
- Verify the CSRF token field name: Use your browser’s developer tools (F12) to inspect the login form. Look for a hidden input field—its
nameattribute is what you need to use inlogin_data(common names are_csrf,authenticity_token, orcsrf_token). - Always use the session object: Never mix direct
requestscalls with yoursession—this ensures cookies (like session IDs) are retained between requests, which is essential for maintaining your login state. - Double-check credentials: You had a typo in your password variable (
passowrinstead ofpassword)—that would cause a login failure even if the CSRF token is correct.
内容的提问来源于stack exchange,提问作者Oladimeji Olaolorun

