运行Nike.com自动注册登录脚本时遭遇401未授权错误求助
Hey there, let's walk through the likely causes of your 401 error and how to fix them step by step:
1. Session Handling Breakage
Looking at your code, after registration you do:
sess1=sess sess=requests.session()
This creates a new, empty session for login, which discards all cookies set during registration. Nike's auth system relies on session consistency—you need to use the same session for both registration and login. Remove that sess=requests.session() line and stick with the original sess object for your login request.
2. Locale & Cookie Inconsistencies
You're hitting the zh_CN locale endpoint for both registration and login, but your payload uses en_US/en_GB depending on the country. This mismatch can trigger auth checks. Fix this by:
- Matching the URL's
localeparameter to your payload'slocalevalue (e.g., uselocale=en_USin the URL when country is US) - Setting all locale-aligned cookies (
CONSUMERCHOICE,NIKE_COMMERCE_LANG_LOCALE, etc.) before making the registration request, not just login.
3. Outdated App/Experience Versions
Nike frequently updates the appVersion and experienceVersion parameters in their API URLs. If your APPVERSION and EXPVERSION variables are static and outdated, the endpoint will reject your request. To fix this:
- Manually visit Nike's website, inspect network traffic for join/login requests, and copy the latest version numbers into your script.
- Consider adding logic to scrape these version numbers dynamically from Nike's homepage HTML to avoid future breaks.
4. Missing or Incorrect Request Headers
Your current headers only include User-Agent, but Nike's API expects additional headers to mimic a real browser. Add these to your session headers:
sess.headers.update({ "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36", "Accept": "application/json, text/plain, */*", "Accept-Language": "en-US,en;q=0.9", "Referer": "https://www.nike.com/", "Origin": "https://www.nike.com" })
Adjust Accept-Language to match your selected locale (e.g., zh-CN,zh;q=0.9 for China).
5. Anti-Bot & Proxy Issues
Nike has strict anti-bot measures:
- Random proxies from
PROXYLISTmight be already blocked by Nike. Test with a fresh, residential proxy instead of datacenter proxies. - Using
verify=Falsecan trigger red flags—use a valid SSL certificate bundle instead, or ensure your proxy handles SSL correctly. - Add small delays between requests (e.g.,
time.sleep(2)after registration) to avoid rate limiting.
6. Payload Parameter Validation
Double-check your login payload:
- The
client_idvalue might be region-specific. Confirm thatHlHa2Cje3ctlaOqnxvgZXNaAs7T9nAuHis the correct client ID for your target region (US/GB/CN). You can find this by inspecting login requests in your browser's dev tools. - Ensure all payload fields (like
grant_type,ux_id) match exactly what Nike's official login form sends.
Quick Adjusted Snippet (US Region Example)
Here's a trimmed version fixing session and locale alignment:
# Set locale/cookies BEFORE registration if country == "US": sess.cookies["CONSUMERCHOICE"] = "us/en_us" sess.cookies["NIKE_COMMERCE_COUNTRY"] = "US" sess.cookies["NIKE_COMMERCE_LANG_LOCALE"] = "en_US" sess.cookies["nike_locale"] = "us/en_US" locale_param = "en_US" else: sess.cookies["CONSUMERCHOICE"] = "gb/en_gb" sess.cookies["NIKE_COMMERCE_COUNTRY"] = "GB" sess.cookies["NIKE_COMMERCE_LANG_LOCALE"] = "en_GB" sess.cookies["nike_locale"] = "gb/en_gb" locale_param = "en_GB" # Registration URL with matching locale reg_url = f"https://unite.nike.com/join?appVersion={APPVERSION}&experienceVersion={EXPVERSION}&uxid=com.nike.commerce.nikedotcom.web&locale={locale_param}&backendEnvironment=identity&browser=Google%20Inc.&os=Windows&mobile=false&native=false" r = sess.post(reg_url, json=payload, verify=True, proxies={"https": prox}) r.raise_for_status() # Use the SAME session for login login_url = f"https://unite.nike.com/loginWithSetCookie?appVersion={APPVERSION}&experienceVersion={EXPVERSION}&uxid=com.nike.commerce.nikedotcom.web&locale={locale_param}&backendEnvironment=identity&browser=Google%20Inc.&os=Windows&mobile=false&native=false" e = sess.post(login_url, json={"username": email, "password": password, "client_id": "HlHa2Cje3ctlaOqnxvgZXNaAs7T9nAuH", "ux_id": "com.nike.commerce.nikedotcom.web", "grant_type": "password"}, verify=True, proxies={"https": prox}) e.raise_for_status()
Start with fixing the session handling and locale mismatch first—those are the most likely culprits for your 401 error.
内容的提问来源于stack exchange,提问作者josiah

