import urllib.request, json, http.cookiejar cj = http.cookiejar.CookieJar() opener = urllib.request.build_opener(urllib.request.HTTPCookieProcessor(cj)) # Get CSRF token csrf = json.loads(opener.open('http://localhost:8301/api/auth/csrf').read()) print('CSRF:', csrf['csrfToken'][:30]) # Dump cookies for debug print('Cookies before login:') for c in cj: print(f' {c.name}={c.value[:30]}... domain={c.domain} path={c.path} secure={c.secure}') # Login data = urllib.parse.urlencode({ 'csrfToken': csrf['csrfToken'], 'email': 'admin@zhuiguang.com', 'password': 'Admin123!' }).encode() print('Posting login with data:', data[:80]) req = urllib.request.Request('http://localhost:8301/api/auth/callback/credentials', data=data, method='POST') try: resp = urllib.request.urlopen(req) print('Status:', resp.status) print('Location:', resp.headers.get('location')) except urllib.error.HTTPError as e: loc = e.headers.get('location', '') print('Status:', e.code) print('Location:', loc) if 'error=CredentialsSignin' in loc: print('FAIL: CredentialsSignin - check email/password') elif 'csrf=true' in loc: print('FAIL: CSRF token mismatch') elif loc.startswith('https://www.zhuig.com'): print('SUCCESS: Login redirect to dashboard') print('\nCookies after login:') for c in cj: if 'next-auth' in c.name or 'session' in c.name: print(f' {c.name}={c.value[:30]}...') # Session try: sess = json.loads(opener.open('http://localhost:8301/api/auth/session').read()) if sess.get('user'): print('SESSION OK - user:', sess['user'].get('email')) else: print('SESSION EMPTY') except Exception as e: print('Session error:', e)