import urllib.request, json, http.cookiejar, http.client # Enable debug to see request headers http.client.HTTPConnection.debuglevel = 1 cj = http.cookiejar.CookieJar() opener = urllib.request.build_opener(urllib.request.HTTPCookieProcessor(cj)) # Get CSRF csrf = json.loads(opener.open('http://localhost:8301/api/auth/csrf').read()) print('\n=== Cookies after CSRF ===') for c in cj: print(f' {c.name}: val={c.value[:30]} domain={c.domain} path={c.path} secure={c.secure} httponly={c.has_nonstandard_attr("HttpOnly")}') # Now login with debug to see if cookies are sent print('\n=== Login POST headers ===') data = urllib.parse.urlencode({ 'csrfToken': csrf['csrfToken'], 'email': 'admin@zhuiguang.com', 'password': 'Admin123!' }).encode() req = urllib.request.Request('http://localhost:8301/api/auth/callback/credentials', data=data, method='POST') # Check what cookies will be sent print(f'Sending cookies:') for c in cj: print(f' {"Cookie: "}{c.name}={c.value[:30]}') try: resp = urllib.request.urlopen(req) print(f'Status: {resp.status}') print(f'Location: {resp.headers.get("location")}') except urllib.error.HTTPError as e: loc = e.headers.get('location', '') print(f'Status: {e.code}') print(f'Location: {loc}') if 'csrf=true' in loc: print('CSRF FAILED') elif loc.startswith('https://www.zhuig.com'): print('LOGIN SUCCESS - redirect to app')