咨询:生成扫码后自动填充网站账号密码的二维码实现方案
Hey there, your idea is totally on the right track—this is absolutely feasible to implement. Let’s break down the step-by-step solution for your iOS 11 use case:
1. Build a URL with Embedded Credentials
First, append your username and password as URL query parameters to your target login page URL. Always URL-encode the parameter values to avoid issues with special characters like &, =, or spaces.
Example encoded URL:https://your-login-site.com/login?username=john_doe&password=Secure%26Pass%3D123
Tip: Use
encodeURIComponent()to safely format credentials before building the URL. For example,encodeURIComponent("Secure&Pass=123")converts toSecure%26Pass%3D123, ensuring the parameters parse correctly.
2. Generate the QR Code
Use your existing QR code tool to create a code for this parameterized URL. When scanned with an iOS 11 camera, it will automatically open the URL in Safari (or your default browser) and load the login page.
3. Add a Script to Parse and Fill Credentials
This is the core piece—you’ll need JavaScript to read the URL parameters and populate the login form without triggering the login button. Here’s how to implement it:
Option A: For a Website You Control
Add this script directly to your login page’s HTML:
// Run once the page is fully loaded document.addEventListener('DOMContentLoaded', () => { // Helper to extract URL parameters const getParams = () => { const params = {}; new URLSearchParams(window.location.search).forEach((val, key) => { params[key] = decodeURIComponent(val); }); return params; }; const credentials = getParams(); // Fill username (replace "username" with your input's actual ID) if (credentials.username) { const userInput = document.getElementById('username'); if (userInput) { userInput.value = credentials.username; // Trigger input event to activate any form validation logic userInput.dispatchEvent(new Event('input')); } } // Fill password (replace "password" with your input's actual ID) if (credentials.password) { const passInput = document.getElementById('password'); if (passInput) { passInput.value = credentials.password; passInput.dispatchEvent(new Event('input')); } } // No login trigger here—we intentionally skip calling form.submit() or button.click() });
Option B: For Third-Party Websites
If you can’t modify the target site’s code, use a user script (like Tampermonkey) to inject the code above. On iOS:
- Use Safari with a userscript extension (e.g., Userscripts)
- Install the extension, then create a new script targeting your login page’s URL
- Paste the code above, adjusting the input IDs to match the site’s form elements
4. iOS 11 Compatibility Check
iOS 11’s Safari fully supports the URLSearchParams API used in the script, so this will work natively. For other browsers on iOS, any modern browser (Chrome, Firefox) will also handle the code without issues.
Critical Security Notes
- Never use this for public or untrusted scenarios: URL query parameters can be logged by servers, proxies, or browser extensions—even over HTTPS. Only use this for internal, personal use where you control the environment.
- Avoid storing sensitive credentials in QR codes long-term; treat them as temporary access tools.
内容的提问来源于stack exchange,提问作者John Doe Python

