54 lines
1.7 KiB
Python
54 lines
1.7 KiB
Python
import urllib.request, json, http.cookiejar
|
|
|
|
cj = http.cookiejar.CookieJar()
|
|
opener = urllib.request.build_opener(urllib.request.HTTPCookieProcessor(cj))
|
|
|
|
# Get CSRF token
|
|
csrf = json.loads(opener.open('http://localhost:8301/api/auth/csrf').read())
|
|
print('CSRF:', csrf['csrfToken'][:30])
|
|
|
|
# Dump cookies for debug
|
|
print('Cookies before login:')
|
|
for c in cj:
|
|
print(f' {c.name}={c.value[:30]}... domain={c.domain} path={c.path} secure={c.secure}')
|
|
|
|
# Login
|
|
data = urllib.parse.urlencode({
|
|
'csrfToken': csrf['csrfToken'],
|
|
'email': 'admin@zhuiguang.com',
|
|
'password': 'Admin123!'
|
|
}).encode()
|
|
|
|
print('Posting login with data:', data[:80])
|
|
|
|
req = urllib.request.Request('http://localhost:8301/api/auth/callback/credentials', data=data, method='POST')
|
|
try:
|
|
resp = urllib.request.urlopen(req)
|
|
print('Status:', resp.status)
|
|
print('Location:', resp.headers.get('location'))
|
|
except urllib.error.HTTPError as e:
|
|
loc = e.headers.get('location', '')
|
|
print('Status:', e.code)
|
|
print('Location:', loc)
|
|
if 'error=CredentialsSignin' in loc:
|
|
print('FAIL: CredentialsSignin - check email/password')
|
|
elif 'csrf=true' in loc:
|
|
print('FAIL: CSRF token mismatch')
|
|
elif loc.startswith('https://www.zhuig.com'):
|
|
print('SUCCESS: Login redirect to dashboard')
|
|
|
|
print('\nCookies after login:')
|
|
for c in cj:
|
|
if 'next-auth' in c.name or 'session' in c.name:
|
|
print(f' {c.name}={c.value[:30]}...')
|
|
|
|
# Session
|
|
try:
|
|
sess = json.loads(opener.open('http://localhost:8301/api/auth/session').read())
|
|
if sess.get('user'):
|
|
print('SESSION OK - user:', sess['user'].get('email'))
|
|
else:
|
|
print('SESSION EMPTY')
|
|
except Exception as e:
|
|
print('Session error:', e)
|