You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:如何通过PHP cURL获取EA登录后的授权Code

Can I use PHP cURL to remotely log into an EA account and retrieve an auth code?

Hey there, let's tackle this question head-on. The short answer is: yes, this is technically possible with PHP cURL, but there are major caveats and security/terms hurdles you need to be aware of before diving in. EA's authentication system is built to block automated scripts (for good security reasons), so you'll have to work around several roadblocks.

First, Let's Break Down the Flow

EA uses OAuth 2.0 for its authentication, and the endpoint you're targeting (/connect/auth) is part of that flow. To get the code you need, you have to:

  • Grab session cookies and security tokens from the EA login page
  • Submit valid login credentials to authenticate the user
  • Use the authenticated session to hit the auth endpoint and fetch the code

Step-by-Step PHP cURL Implementation (Rough Outline)

Here's a basic framework to get you started—note that this will need adjustments as EA's page structure and anti-bot measures change:

1. Fetch the Login Page to Capture Cookies & CSRF Tokens

First, you need to load the EA profile login page to grab initial cookies and extract any required security tokens (like CSRF tokens) from the HTML.

// Initialize cURL session
$ch = curl_init();

// Set options to mimic a real browser
curl_setopt($ch, CURLOPT_URL, 'https://profile.ea.com/');
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_COOKIEJAR, 'ea_session_cookies.txt'); // Store cookies in a file
curl_setopt($ch, CURLOPT_COOKIEFILE, 'ea_session_cookies.txt'); // Use stored cookies for subsequent requests
curl_setopt($ch, CURLOPT_USERAGENT, 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36');
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); // Follow redirects

// Fetch the login page
$loginPageHtml = curl_exec($ch);

// Extract CSRF token (you'll need to update the regex if EA changes the form field name)
preg_match('/<input type="hidden" name="csrf_token" value="([^"]+)"/i', $loginPageHtml, $csrfMatches);
$csrfToken = $csrfMatches[1] ?? '';

if (empty($csrfToken)) {
    die("Failed to extract CSRF token—EA's login page structure may have changed.");
}

2. Submit Login Credentials

Next, send a POST request with the user's email/password, along with the CSRF token and stored cookies.

// Prepare login form data (check the actual login form fields on EA's page to confirm all required params)
$loginPostData = http_build_query([
    'email' => 'your_ea_email@example.com',
    'password' => 'your_ea_password',
    'csrf_token' => $csrfToken,
    'rememberMe' => 'on' // Optional, depending on EA's form
]);

// Update cURL options for login POST request
curl_setopt($ch, CURLOPT_URL, 'https://profile.ea.com/login.do'); // Verify the correct login endpoint
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, $loginPostData);

// Execute login request
$loginResponse = curl_exec($ch);

// Check if login succeeded—you can verify by looking for specific cookies or parsing the response HTML
// For example, check if the response redirects to the EA dashboard or contains a success message

3. Retrieve the Auth Code

Once logged in, hit the auth endpoint you mentioned to get the JSON response with the code.

// Update cURL options for the auth code request
curl_setopt($ch, CURLOPT_URL, 'https://accounts.ea.com/connect/auth?client_id=sparta-companion-web&response_type=code&prompt=none&redirect_uri=nucleus:rest');
curl_setopt($ch, CURLOPT_POST, false); // This is a GET request
curl_setopt($ch, CURLOPT_HTTPHEADER, [
    'Accept: application/json' // Ensure we get a JSON response
]);

// Fetch the auth response
$authResponse = curl_exec($ch);

// Parse the JSON to extract the code
$authData = json_decode($authResponse, true);
$authCode = $authData['code'] ?? '';

if (!empty($authCode)) {
    echo "Success! Auth code: " . $authCode;
} else {
    echo "Failed to retrieve auth code—check if login was successful or if EA blocked the request.";
}

// Close the cURL session
curl_close($ch);

Critical Hurdles & Warnings

  • CAPTCHA Blocks: EA will almost certainly trigger a CAPTCHA if it detects automated traffic. Bypassing this requires manual input or third-party services, which violates EA's Terms of Service.
  • Terms of Service Violation: Automating access to EA's services is likely against their TOS. Your EA account could be permanently banned if you're caught.
  • Dynamic Page Changes: EA regularly updates its login page structure (token names, form fields, etc.), so your parsing logic will break frequently.
  • Session Security: EA's cookies have short lifespans, and they may invalidate sessions if they detect unusual activity (like repeated automated logins from the same IP).

Final Recommendation

While the technical implementation works in theory, the practical risks (account bans, constant maintenance, legal issues) make this a bad approach for most use cases. If you're building a legitimate tool, look into EA's official developer resources (if available) for authorized API access instead.

内容的提问来源于stack exchange,提问作者Phil Elaidez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 10:09:57