PHP登录网站获取Cookie求助:Binweevils登录Cookie获取失败
Hey there, let's troubleshoot this Cookie issue with Binweevils together. I've run into similar problems with sites that enforce strict Cookie checks beyond just API parameters, so here are some actionable steps to help you get those Cookies:
1. Mimic a Real Browser's Request Flow
Most sites don't just look at your API parameters—they verify that the request comes from a legitimate browser. Here's what you need to do:
- First, send a GET request to the Binweevils login page before submitting your login data. This lets the site set initial session Cookies that are required for subsequent login attempts.
- Include essential browser headers in all your requests:
User-Agent: Use a real browser string (e.g.,Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36)Referer: Set this to the login page URL (e.g.,https://www.binweevils.com/login/)Accept: Match what a browser sends (e.g.,text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8)
2. Use a Session to Persist Cookies
If you're using a script (like Python's requests library), never make isolated requests—use a Session object to automatically store and reuse Cookies across requests. Example:
import requests # Initialize a session to keep track of Cookies session = requests.Session() # First, fetch the login page to get initial session Cookies session.get("https://www.binweevils.com/login/") # Prepare your login parameters (add any required fields like CSRF token here) login_payload = { "username": "your_username", "password": "your_password", # Check the login page's HTML for a CSRF token and include it here if present } # Submit the login request login_response = session.post("https://www.binweevils.com/api/login/", data=login_payload) # Access the logged-in Cookies from the session print("Logged-in Cookies:", session.cookies.get_dict())
Note: Many sites require a CSRF token (found in the login page's HTML). Use a parser like BeautifulSoup to extract it and add it to your payload.
3. Handle JavaScript-Generated Cookies
Some sites use JavaScript to set critical Cookies that pure HTTP requests can't capture. For these cases, use a headless browser tool to simulate real user behavior:
from playwright.sync_api import sync_playwright with sync_playwright() as p: # Launch a headless Chrome browser browser = p.chromium.launch(headless=True) page = browser.new_page() # Navigate to the login page (executes JS and sets initial Cookies) page.goto("https://www.binweevils.com/login/") # Fill out the login form page.fill("#username", "your_username") page.fill("#password", "your_password") page.click("button[type='submit']") # Wait for login to complete and fetch all Cookies page.wait_for_url("https://www.binweevils.com/dashboard/") cookies = page.context.cookies() print("All Cookies:", cookies) browser.close()
This method replicates exactly what a human user does, so it bypasses JS-based Cookie checks.
4. Check for Redirects or Additional Verification
- Ensure your request follows redirects (most libraries like
requestsdo this by default). Some sites redirect after login, and the final Cookies are set during this redirect. - Watch out for CAPTCHAs or other verification steps. If the site requires this, you'll need to handle it manually or use a verification service (though this adds complexity).
内容的提问来源于stack exchange,提问作者James Tyreece

