如何通过POST请求登录https://analytics.oag.com/analyser-client/home?
How to Fix Your Curl Login Request for analytics.oag.com
Let’s walk through what’s off with your current curl command and how to fix it to successfully log in to the site:
Key Issues in Your Current Command
- Duplicate request headers: You included
Accept-Languagetwice in your command. This is redundant and might even cause the server to ignore the header entirely—just keep one instance. - Incorrect Content-Type: You’re sending JSON data (
{"username":"test","password":"test"}) but setContent-Type: text/html;charset=UTF-8. Servers rely on this header to parse the request body, so this mismatch means your credentials won’t be recognized. Switch this toapplication/json. - Wrong target URL: Most sites don’t handle login requests directly on the home page (
/analyser-client/home). You need to find the actual login API endpoint first.
Step-by-Step Fixes
1. Locate the Correct Login Endpoint
First, use your browser’s developer tools to find where the login request is actually sent:
- Open Chrome/Firefox DevTools (F12), go to the Network tab
- Log in to the site normally
- Look for a POST request (usually to paths like
/login,/api/auth/login, or/analyser-client/api/login)—that’s the URL you need to target with curl.
2. Handle Cookies for Session Persistence
Login sessions rely on cookies, so curl needs to save and reuse them:
- Use
-c cookies.txtto save cookies from the server response - Use
-b cookies.txtto send saved cookies in subsequent requests
3. (Optional) Handle CSRF Tokens
Many sites use CSRF tokens to prevent malicious requests. If the login form has one:
- First, fetch the login page to get the token:
curl 'https://analytics.oag.com/analyser-client/login' -c cookies.txt -s | grep -o '<input name="csrfToken" value="[^"]*"' | cut -d '"' -f 4 > csrf-token.txt - Include the token in your login request (either in the request body or a header like
X-CSRF-Token—check what your browser sends).
4. Corrected Curl Command Example
Assuming you found the login endpoint is /api/auth/login, here’s a revised command:
curl 'https://analytics.oag.com/api/auth/login' \ -H 'Accept-Language: en-US,en;q=0.9' \ -H 'Connection: keep-alive' \ -H 'Host: analytics.oag.com' \ -H 'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.181 Safari/537.36' \ -H 'Content-Type: application/json' \ # Uncomment the line below if you need a CSRF token # -H 'X-CSRF-Token: '"$(cat csrf-token.txt)" \ -b cookies.txt \ -c cookies.txt \ --data '{"username":"test","password":"test"}'
5. Access the Home Page After Login
Once you’ve successfully logged in, use the saved cookies to access the home page:
curl 'https://analytics.oag.com/analyser-client/home' -b cookies.txt
Additional Notes
- If the site uses captchas or OAuth-based login, curl alone might not work—you’d need tools like Selenium to handle interactive steps.
- Always match the exact headers your browser sends (check the Network tab) for things like
Refereror additional auth-related headers.
内容的提问来源于stack exchange,提问作者Tiantian Tian
相关产品推荐
相关产品推荐

