import urllib.request, json, http.cookiejar, urllib.error cj = http.cookiejar.CookieJar() opener = urllib.request.build_opener(urllib.request.HTTPCookieProcessor(cj)) # Get CSRF token csrf_resp = opener.open('http://localhost:8301/api/auth/csrf') csrf = json.loads(csrf_resp.read()) print('CSRF token:', csrf['csrfToken'][:20] + '...') # Login data = urllib.parse.urlencode({ 'csrfToken': csrf['csrfToken'], 'email': 'admin@zhuiguang.com', 'password': 'Admin123!' }).encode() req = urllib.request.Request( 'http://localhost:8301/api/auth/callback/credentials', data=data, method='POST' ) try: login_resp = opener.open(req) print('Login status:', login_resp.status) loc = login_resp.headers.get('location', 'none') print('Location:', loc) except urllib.error.HTTPError as e: loc = e.headers.get('location', 'none') print('Login redirect:', e.code, '->', loc) if 'error=CredentialsSignin' in (loc or ''): print('>>> ERROR: Invalid credentials!') elif 'csrf=true' in (loc or ''): print('>>> ERROR: CSRF token mismatch!') # Session sess_resp = opener.open('http://localhost:8301/api/auth/session') sess = json.loads(sess_resp.read()) print('Session:', json.dumps(sess, indent=2))