使用Python Requests登录ASPX校园网站遇SubmitButton坐标参数问题
Hey there! I’ve wrestled with this exact ASP.NET login weirdness before, so let me break down how to get past it.
First, let’s demystify those SubmitButton.x and SubmitButton.y parameters: they’re just the pixel coordinates where you clicked the submit button. ASP.NET uses these to figure out which button was triggered (useful if there are multiple buttons on a page), but for most basic login forms, the actual values barely matter—any integer pair will work.
Your failed attempt with manual values likely isn’t because of these coordinates, but because you missed other critical ASPX hidden parameters that change on every request. Here’s the step-by-step fix:
1. Grab all dynamic hidden parameters first
ASPX pages rely on hidden fields like __VIEWSTATE, __VIEWSTATEGENERATOR, and __EVENTVALIDATION to maintain state. You can’t hardcode these—you need to fetch them fresh from the login page each time.
Use requests.Session() to keep your cookies (critical for maintaining session state) and parse the page with BeautifulSoup:
import requests from bs4 import BeautifulSoup # Initialize a session to persist cookies session = requests.Session() login_page_url = "https://your-campus-login-url.aspx" # Mimic a browser's User-Agent to avoid being blocked headers = { "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" } # Fetch the login page to get hidden parameters login_page = session.get(login_page_url, headers=headers) soup = BeautifulSoup(login_page.text, "html.parser") # Extract the required hidden fields viewstate = soup.find("input", attrs={"name": "__VIEWSTATE"})["value"] viewstate_generator = soup.find("input", attrs={"name": "__VIEWSTATEGENERATOR"})["value"] event_validation = soup.find("input", attrs={"name": "__EVENTVALIDATION"})["value"]
2. Build your login payload correctly
Include all the fields from the login form—your username, password, the hidden parameters above, and the SubmitButton.x/y values (use any integers, like 10/10). Double-check the field names against what you saw in your manual login form data (case-sensitive!):
login_payload = { "__VIEWSTATE": viewstate, "__VIEWSTATEGENERATOR": viewstate_generator, "__EVENTVALIDATION": event_validation, "UsernameFieldName": "your-username", # Replace with actual field name from your form "PasswordFieldName": "your-password", # Replace with actual field name from your form "SubmitButton.x": 10, "SubmitButton.y": 10, "SubmitButton": "Login" # Match the button's value from your form (might be empty string) }
3. Send the login POST request
Use your session to send the payload, and verify success by checking for content that only appears after login (like a welcome message or your username):
# Send the login request login_response = session.post(login_page_url, data=login_payload, headers=headers) # Check if login worked if "Welcome, " in login_response.text or "Dashboard" in login_response.text: print("Login successful! You can now scrape data with this session.") else: print("Login failed. Double-check field names, credentials, or look for missing parameters.")
Troubleshooting tips if it still fails
- Compare your payload with browser traffic: Use your browser’s DevTools (F12 > Network tab) to capture the actual POST data when you log in manually. Cross-reference every field name and value with what you’re sending—even a tiny typo (like missing underscores in
__VIEWSTATE) will break it. - Check for captchas: If your campus site uses captchas, you’ll need to handle those separately (maybe with a service or manual input).
- Verify cookies: The
requests.Session()should handle cookies automatically, but if not, you can manually inspect and add them to your headers.
内容的提问来源于stack exchange,提问作者Kornishock

