全项目扫描修复: Docker数据卷修复+安全requireAdmin+12页SEO+API白名单+脚本超时+常量提取+假数据删除
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
import urllib.request, json, http.cookiejar, urllib.error
|
||||
|
||||
cj = http.cookiejar.CookieJar()
|
||||
opener = urllib.request.build_opener(urllib.request.HTTPCookieProcessor(cj))
|
||||
|
||||
# Get CSRF token
|
||||
csrf_resp = opener.open('http://localhost:8301/api/auth/csrf')
|
||||
csrf = json.loads(csrf_resp.read())
|
||||
print('CSRF token:', csrf['csrfToken'][:20] + '...')
|
||||
|
||||
# Login
|
||||
data = urllib.parse.urlencode({
|
||||
'csrfToken': csrf['csrfToken'],
|
||||
'email': 'admin@zhuiguang.com',
|
||||
'password': 'Admin123!'
|
||||
}).encode()
|
||||
|
||||
req = urllib.request.Request(
|
||||
'http://localhost:8301/api/auth/callback/credentials',
|
||||
data=data,
|
||||
method='POST'
|
||||
)
|
||||
|
||||
try:
|
||||
login_resp = opener.open(req)
|
||||
print('Login status:', login_resp.status)
|
||||
loc = login_resp.headers.get('location', 'none')
|
||||
print('Location:', loc)
|
||||
except urllib.error.HTTPError as e:
|
||||
loc = e.headers.get('location', 'none')
|
||||
print('Login redirect:', e.code, '->', loc)
|
||||
if 'error=CredentialsSignin' in (loc or ''):
|
||||
print('>>> ERROR: Invalid credentials!')
|
||||
elif 'csrf=true' in (loc or ''):
|
||||
print('>>> ERROR: CSRF token mismatch!')
|
||||
|
||||
# Session
|
||||
sess_resp = opener.open('http://localhost:8301/api/auth/session')
|
||||
sess = json.loads(sess_resp.read())
|
||||
print('Session:', json.dumps(sess, indent=2))
|
||||
Reference in New Issue
Block a user