🚀调整项目结构
This commit is contained in:
636
docs/login/login_action/QR.md
Normal file
636
docs/login/login_action/QR.md
Normal file
@@ -0,0 +1,636 @@
|
||||
# 二维码登录
|
||||
|
||||
<img src="../../../assets/img/2233login.png"/>
|
||||
|
||||
- [扫码登录流程(伪代码)](#扫码登录流程伪代码)
|
||||
- [web端扫码登录](#web端扫码登录)
|
||||
- [申请二维码(web端)](#申请二维码web端)
|
||||
- [扫码登录(web端)](#扫码登录web端)
|
||||
- [web端扫码登录-旧版](#web端扫码登录-旧版)
|
||||
- [申请二维码(web端-旧版)](#申请二维码web端-旧版)
|
||||
- [扫码登录(web端-旧版)](#扫码登录web端-旧版)
|
||||
- [TV端扫码登录](#TV端扫码登录)
|
||||
- [申请二维码(TV端)](#申请二维码TV端)
|
||||
- [扫码登录(TV端)](#扫码登录TV端)
|
||||
|
||||
---
|
||||
|
||||
## 扫码登录流程(伪代码)
|
||||
|
||||
```python
|
||||
token, url = 申请二维码()
|
||||
生成二维码(url) # 等待客户端扫码
|
||||
while True:
|
||||
status, cookie = 扫码登录(token)
|
||||
match status:
|
||||
case 未扫描:
|
||||
continue
|
||||
case 二维码超时 | 二维码失效:
|
||||
提示('二维码失效或超时') # 需要用户重新操作
|
||||
break
|
||||
case 已扫描未确认:
|
||||
提示('扫描成功')
|
||||
case 登录成功:
|
||||
提示('扫描成功')
|
||||
存储cookie(cookie)
|
||||
SSO登录页面跳转()
|
||||
break
|
||||
```
|
||||
|
||||
## web端扫码登录
|
||||
|
||||
### 申请二维码(web端)
|
||||
|
||||
> https://passport.bilibili.com/x/passport-login/web/qrcode/generate
|
||||
|
||||
*请求方式:GET*
|
||||
|
||||
密钥超时为180秒
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------|-----|------|------|
|
||||
| code | num | 返回值 | 0:成功 |
|
||||
| message | str | 错误信息 | |
|
||||
| ttl | num | 1 | |
|
||||
| data | obj | 信息本体 | |
|
||||
|
||||
`data`对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|------------|-----|------------------|--------|
|
||||
| url | str | 二维码内容 (登录页面 url) | |
|
||||
| qrcode_key | str | 扫码登录秘钥 | 恒为32字符 |
|
||||
|
||||
**示例:**
|
||||
|
||||
`url`中的值生成二维码,等待手机客户端扫描,并将`qrcode_key`保存备用
|
||||
|
||||
```shell
|
||||
curl 'https://passport.bilibili.com/x/passport-login/web/qrcode/generate'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"message": "0",
|
||||
"ttl": 1,
|
||||
"data": {
|
||||
"url": "https://passport.bilibili.com/h5-app/passport/login/scan?navhide=1\u0026qrcode_key=8587cf8106a0b863c46d6bab913537f6\u0026from=",
|
||||
"qrcode_key": "8587cf8106a0b863c46d6bab913537f6"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
### 扫码登录(web端)
|
||||
|
||||
> https://passport.bilibili.com/x/passport-login/web/qrcode/poll
|
||||
|
||||
*请求方式:GET*
|
||||
|
||||
密钥超时为180秒
|
||||
|
||||
验证登录成功后会进行设置以下cookie项:
|
||||
|
||||
`DedeUserID` `DedeUserID__ckMd5` `SESSDATA` `bili_jct`
|
||||
|
||||
**url参数:**
|
||||
|
||||
| 参数名 | 类型 | 内容 | 必要性 | 备注 |
|
||||
|------------|-----|--------|-----|-----|
|
||||
| qrcode_key | str | 扫码登录秘钥 | 非必要 | |
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------|-----|------|------|
|
||||
| code | num | 返回值 | 0:成功 |
|
||||
| message | str | 错误信息 | |
|
||||
| data | obj | 信息本体 | |
|
||||
|
||||
data 对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------------|-----|----------------------------------------------------------------|------------------------|
|
||||
| url | str | 游戏分站跨域登录 url | 未登录为空 |
|
||||
| refresh_token | str | 刷新`refresh_token` | 未登录为空 |
|
||||
| timestamp | num | 登录时间 | 未登录为`0`<br />时间戳 单位为毫秒 |
|
||||
| code | num | 0:扫码登录成功<br />86038:二维码已失效<br />86090:二维码已扫码未确认<br />86101:未扫码 | |
|
||||
| message | str | 扫码状态信息 | |
|
||||
|
||||
**示例:**
|
||||
|
||||
使用扫描秘钥`c3bd5286a2b40a822f5f60e9bf3f602e`登录
|
||||
|
||||
```shell
|
||||
curl -G "https://passport.bilibili.com/x/passport-login/web/qrcode/poll"\
|
||||
--data-urlencode 'qrcode_key=c3bd5286a2b40a822f5f60e9bf3f602e' \
|
||||
-c 'cookie.txt'
|
||||
```
|
||||
|
||||
当密钥正确时但未扫描时`code`为`86101`
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"message": "0",
|
||||
"ttl": 1,
|
||||
"data": {
|
||||
"url": "",
|
||||
"refresh_token": "",
|
||||
"timestamp": 0,
|
||||
"code": 86101,
|
||||
"message": "未扫码"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
扫描成功但手机端未确认时`code`为`86090`
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"message": "0",
|
||||
"ttl": 1,
|
||||
"data": {
|
||||
"url": "",
|
||||
"refresh_token": "",
|
||||
"timestamp": 0,
|
||||
"code": 86090,
|
||||
"message": "二维码已扫码未确认"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
扫描成功手机端确认登录后,`code`为`0`,并向浏览器写入cookie
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"message": "0",
|
||||
"ttl": 1,
|
||||
"data": {
|
||||
"url": "https://passport.biligame.com/crossDomain?DedeUserID=***\u0026DedeUserID__ckMd5=***\u0026Expires=***\u0026SESSDATA=***\u0026bili_jct=***\u0026gourl=https%3A%2F%2Fpassport.bilibili.com",
|
||||
"refresh_token": "***",
|
||||
"timestamp": 1662363009601,
|
||||
"code": 0,
|
||||
"message": ""
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
**响应头部抓包信息:**
|
||||
|
||||
可明显看见设置了几个cookie
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```http
|
||||
HTTP/1.1 200 OK
|
||||
Date: Mon, 05 Sep 2022 07:30:09 GMT
|
||||
Expires: Mon, 05 Sep 2022 07:30:08 GMT
|
||||
Cache-control: no-cache
|
||||
Content-encoding: br
|
||||
Content-type: application/json; charset=utf-8
|
||||
bili-status-code: 0
|
||||
bili-trace-id: 0d23fe044a6315a5
|
||||
set-cookie: SESSDATA=***; Path=/; Domain=bilibili.com; Expires=Sat, 04 Mar 2023 07:30:09 GMT; HttpOnly; Secure
|
||||
set-cookie: bili_jct=***; Path=/; Domain=bilibili.com; Expires=Sat, 04 Mar 2023 07:30:09 GMT
|
||||
set-cookie: DedeUserID=***; Path=/; Domain=bilibili.com; Expires=Sat, 04 Mar 2023 07:30:09 GMT
|
||||
set-cookie: DedeUserID__ckMd5=***; Path=/; Domain=bilibili.com; Expires=Sat, 04 Mar 2023 07:30:09 GMT
|
||||
set-cookie: sid=***; Path=/; Domain=bilibili.com; Expires=Sat, 04 Mar 2023 07:30:09 GMT
|
||||
x-bili-trace-id: 2fbd8abd97dbd4db0d23fe044a6315a5
|
||||
x-cache-webcdn: BYPASS from blzone02
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
二维码失效时`code`为`86038`
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"message": "0",
|
||||
"ttl": 1,
|
||||
"data": {
|
||||
"url": "",
|
||||
"refresh_token": "",
|
||||
"timestamp": 0,
|
||||
"code": 86038,
|
||||
"message": "二维码已失效"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
## web端扫码登录-旧版
|
||||
|
||||
以下为旧版扫码登录 API,尚可正常访问
|
||||
|
||||
### 申请二维码(web端-旧版)
|
||||
|
||||
> https://passport.bilibili.com/qrcode/getLoginUrl
|
||||
|
||||
*请求方式:GET*
|
||||
|
||||
密钥超时为180秒
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|--------|------|------|--------|
|
||||
| code | num | 返回值 | 0:成功 |
|
||||
| status | bool | true | 作用尚不明确 |
|
||||
| ts | num | 请求时间 | 时间戳 |
|
||||
| data | obj | 信息本体 | |
|
||||
|
||||
`data`对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|----------|-----|------------------|--------|
|
||||
| url | str | 二维码内容 (登录页面 url) | |
|
||||
| oauthKey | str | 扫码登录秘钥 | 恒为32字符 |
|
||||
|
||||
**示例:**
|
||||
|
||||
`url`中的值生成二维码,等待手机客户端扫描,并将`oauthKey`保存备用
|
||||
|
||||
```shell
|
||||
curl 'https://passport.bilibili.com/qrcode/getLoginUrl'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"status": true,
|
||||
"ts": 1583314311,
|
||||
"data": {
|
||||
"url": "https://passport.bilibili.com/qrcode/h5/login?oauthKey=c3bd5286a2b40a822f5f60e9bf3f602e",
|
||||
"oauthKey": "c3bd5286a2b40a822f5f60e9bf3f602e"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
### 扫码登录(web端-旧版)
|
||||
|
||||
> https://passport.bilibili.com/qrcode/getLoginInfo
|
||||
|
||||
*请求方式:POST*
|
||||
|
||||
密钥超时为180秒
|
||||
|
||||
验证登录成功后会进行设置以下cookie项:
|
||||
|
||||
`DedeUserID` `DedeUserID__ckMd5` `SESSDATA` `bili_jct`
|
||||
|
||||
**正文参数( application/x-www-form-urlencoded ):**
|
||||
|
||||
| 参数名 | 类型 | 内容 | 必要性 | 备注 |
|
||||
|----------|-----|--------|-----|----------------------------|
|
||||
| oauthKey | str | 扫码登录秘钥 | 必要 | |
|
||||
| gourl | str | 跳转url | 非必要 | 默认为http://www.bilibili.com |
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------|----------------------|---------------------------|---------------------------------------------------------|
|
||||
| code | num | 返回值 | 0:成功 |
|
||||
| message | str | | 正确无 |
|
||||
| ts | num | 扫码时间 | 错误无 |
|
||||
| status | bool | 扫码是否成功 | true:成功<br />false:未成功 |
|
||||
| data | 正确时:obj<br />错误时:num | 正确时:游戏分站url<br />错误时:错误代码 | 未成功时:<br />-1:密钥错误<br />-2:密钥超时<br />-4:未扫描<br />-5:未确认 |
|
||||
|
||||
data 对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|-----|-----|--------------|-----|
|
||||
| url | str | 游戏分站跨域登录 url | |
|
||||
|
||||
**示例:**
|
||||
|
||||
使用扫描秘钥`c3bd5286a2b40a822f5f60e9bf3f602e`登录
|
||||
|
||||
```shell
|
||||
curl "https://passport.bilibili.com/qrcode/getLoginInfo"\
|
||||
--data-urlencode 'oauthKey=c3bd5286a2b40a822f5f60e9bf3f602e' \
|
||||
-c 'cookie.txt'
|
||||
```
|
||||
|
||||
当密钥正确时但未扫描时`status`为`false`,`data`为`-4`
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"status":false,
|
||||
"data":-4,
|
||||
"message":"Can't scan~"
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
扫描成功但手机端未确认时`status`为`false`,`data`为`-5`
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"status":false,
|
||||
"data":-5,
|
||||
"message":"Can't confirm~"
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
扫描成功手机端确认登录后,`status`为`true`,`data`为对象,并向浏览器写入cookie
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"status": true,
|
||||
"ts": 1583315474,
|
||||
"data": {
|
||||
"url": "https://passport.biligame.com/crossDomain?DedeUserID=***&DedeUserID__ckMd5=***&Expires=***&SESSDATA=***&bili_jct=***&gourl=http%3A%2F%2Fwww.bilibili.com"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
**响应头部抓包信息:**
|
||||
|
||||
可明显看见设置了几个cookie
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```http
|
||||
HTTP/1.1 200 OK
|
||||
Date: Wed, 04 Mar 2020 10:36:37 GMT
|
||||
Content-Type: application/json;charset=UTF-8
|
||||
Transfer-Encoding: chunked
|
||||
Connection: keep-alive
|
||||
Server: Apache-Coyote/1.1
|
||||
Set-Cookie: sid=***; Domain=.bilibili.com; Expires=Thu, 04-Mar-2021 10:36:37 GMT; Path=/
|
||||
Set-Cookie: DedeUserID=***; Domain=.bilibili.com; Expires=Mon, 31-Aug-2020 10:19:57 GMT; Path=/
|
||||
Set-Cookie: DedeUserID__ckMd5=***; Domain=.bilibili.com; Expires=Mon, 31-Aug-2020 10:19:57 GMT; Path=/
|
||||
Set-Cookie: SESSDATA=***; Domain=.bilibili.com; Expires=Mon, 31-Aug-2020 10:19:57 GMT; Path=/; HttpOnly
|
||||
Set-Cookie: bili_jct=***; Domain=.bilibili.com; Expires=Mon, 31-Aug-2020 10:19:57 GMT; Path=/
|
||||
Expires: Wed, 04 Mar 2020 10:36:36 GMT
|
||||
Cache-Control: no-cache
|
||||
X-Cache-Webcdn: BYPASS from ks-sxhz-dx-w-01
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
## TV端扫码登录
|
||||
|
||||
### 申请二维码(TV端)
|
||||
|
||||
> https://passport.snm0516.aisee.tv/x/passport-tv-login/qrcode/auth_code
|
||||
>
|
||||
> https://passport.bilibili.com/x/passport-tv-login/qrcode/auth_code
|
||||
|
||||
*请求方式:POST*
|
||||
|
||||
鉴权方式:appkey
|
||||
|
||||
密钥超时为180秒
|
||||
|
||||
本接口可申请用于TV端APP方式登录的`access_key`
|
||||
|
||||
**正文参数( application/x-www-form-urlencoded ):**
|
||||
|
||||
| 参数名 | 类型 | 内容 | 必要性 | 备注 |
|
||||
| -------- | ---- | ---------- | ------------ | -------------------------- |
|
||||
| appkey | str | APP 密钥 | APP 方式必要 | 仅可用`4409e2ce8ffd12b8` |
|
||||
| local_id | str | TV 端 id | TV 端必要 | 可为`0` |
|
||||
| ts | num | 当前时间戳 | APP 方式必要 | |
|
||||
| sign | str | APP 签名 | APP 方式必要 | |
|
||||
| mobi_app | str | 平台标识 | 非必要 | 会被拼接到返回的 url query |
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------|-----|------|---------------------------------------|
|
||||
| code | num | 返回值 | 0:成功<br />-3:API校验密匙错误<br />-400:请求错误 |
|
||||
| message | str | 错误信息 | 默认为0 |
|
||||
| ttl | num | 1 | |
|
||||
| data | obj | 信息本体 | |
|
||||
|
||||
`data`对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
| --------- | ---- | -------------- | ------------ |
|
||||
| url | str | 二维码内容 url | |
|
||||
| auth_code | str | 扫码登录秘钥 | 恒为 32 字符 |
|
||||
|
||||
**示例:**
|
||||
|
||||
```shell
|
||||
curl 'https://passport.snm0516.aisee.tv/x/passport-tv-login/qrcode/auth_code' \
|
||||
--data-urlencode 'appkey=4409e2ce8ffd12b8' \
|
||||
--data-urlencode 'local_id=0' \
|
||||
--data-urlencode 'ts=0' \
|
||||
--data-urlencode 'sign=e134154ed6add881d28fbdf68653cd9c'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"message": "0",
|
||||
"ttl": 1,
|
||||
"data": {
|
||||
"url": "https://passport.bilibili.com/x/passport-tv-login/h5/qrcode/auth?auth_code=0eeb635a64526709d70cb4c854a3b001",
|
||||
"auth_code": "0eeb635a64526709d70cb4c854a3b001"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
### 扫码登录(TV端)
|
||||
|
||||
> https://passport.snm0516.aisee.tv/x/passport-tv-login/qrcode/poll
|
||||
>
|
||||
> https://passport.bilibili.com/x/passport-tv-login/qrcode/poll
|
||||
|
||||
*请求方式:POST*
|
||||
|
||||
鉴权方式:appkey
|
||||
|
||||
密钥超时为180秒
|
||||
|
||||
验证登录成功后会返回可用于APP方式登录的`access_key`以及`refresh_token`
|
||||
|
||||
**正文参数 (application/x-www-form-urlencoded):**
|
||||
|
||||
| 参数名 | 类型 | 内容 | 必要性 | 备注 |
|
||||
|-----------|-----|-------|---------|-----------------------|
|
||||
| appkey | str | APP密钥 | APP方式必要 | 仅可用`4409e2ce8ffd12b8` |
|
||||
| auth_code | str | 扫码秘钥 | 必要 | |
|
||||
| local_id | str | TV端id | TV端必要 | 可为0 |
|
||||
| ts | num | 当前时间戳 | APP方式必要 | |
|
||||
| sign | str | APP签名 | APP方式必要 | |
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------|-----------------------|------|--------------------------------------------------------------------------------------------------------------|
|
||||
| code | num | 返回值 | 0:成功<br />-3:API校验密匙错误<br />-400:请求错误<br/>-404:啥都木有<br />86038:二维码已失效<br />86039:二维码尚未确认<br/>86090:二维码已扫码未确认 |
|
||||
| message | str | 错误信息 | 默认为0 |
|
||||
| ttl | num | 1 | |
|
||||
| data | 有效时:obj<br />无效时:null | 信息本体 | |
|
||||
|
||||
`data`对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------------|-----|------------|---------------------|
|
||||
| mid | num | 登录用户mid | |
|
||||
| access_token | str | APP登录Token | |
|
||||
| refresh_token | str | APP刷新Token | |
|
||||
| expires_in | num | 有效时间 | 默认:15552000秒,等于180天 |
|
||||
|
||||
**示例:**
|
||||
|
||||
使用扫描秘钥`6214464b3025541abf6f654cf7569a01`进行验证登录
|
||||
|
||||
```shell
|
||||
curl 'https://passport.snm0516.aisee.tv/x/passport-tv-login/qrcode/poll' \
|
||||
--data-urlencode 'appkey=4409e2ce8ffd12b8' \
|
||||
--data-urlencode 'auth_code=6214464b3025541abf6f654cf7569a01' \
|
||||
--data-urlencode 'local_id=0' \
|
||||
--data-urlencode 'ts=0' \
|
||||
--data-urlencode 'sign=87de3d0fee7c3f4facd244537238914e'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"message": "0",
|
||||
"ttl": 1,
|
||||
"data": {
|
||||
"is_new": false,
|
||||
"mid": 10086,
|
||||
"access_token": "********************************",
|
||||
"refresh_token": "********************************",
|
||||
"expires_in": 15552000,
|
||||
"token_info": {
|
||||
"mid": 10086,
|
||||
"access_token": "********************************",
|
||||
"refresh_token": "********************************",
|
||||
"expires_in": 15552000
|
||||
},
|
||||
"cookie_info": {
|
||||
"cookies": [
|
||||
{
|
||||
"name": "SESSDATA",
|
||||
"value": "********************************",
|
||||
"http_only": 1,
|
||||
"expires": 1679988973,
|
||||
"secure": 0
|
||||
},
|
||||
{
|
||||
"name": "bili_jct",
|
||||
"value": "********************************",
|
||||
"http_only": 0,
|
||||
"expires": 1679988973,
|
||||
"secure": 0
|
||||
},
|
||||
{
|
||||
"name": "DedeUserID",
|
||||
"value": "*******",
|
||||
"http_only": 0,
|
||||
"expires": 1679988973,
|
||||
"secure": 0
|
||||
},
|
||||
{
|
||||
"name": "DedeUserID__ckMd5",
|
||||
"value": "****************",
|
||||
"http_only": 0,
|
||||
"expires": 1679988973,
|
||||
"secure": 0
|
||||
},
|
||||
{
|
||||
"name": "sid",
|
||||
"value": "********",
|
||||
"http_only": 0,
|
||||
"expires": 1679988973,
|
||||
"secure": 0
|
||||
}
|
||||
],
|
||||
"domains": [
|
||||
".bilibili.com",
|
||||
".biligame.com",
|
||||
".bigfun.cn",
|
||||
".bigfunapp.cn",
|
||||
".dreamcast.hk"
|
||||
]
|
||||
},
|
||||
"sso": [
|
||||
"https://passport.bilibili.com/api/v2/sso",
|
||||
"https://passport.biligame.com/api/v2/sso",
|
||||
"https://passport.bigfunapp.cn/api/v2/sso"
|
||||
]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
258
docs/login/login_action/SMS.md
Normal file
258
docs/login/login_action/SMS.md
Normal file
@@ -0,0 +1,258 @@
|
||||
# 短信登录
|
||||
|
||||
- [获取国际冠字码_web端](#获取国际冠字码_web端)
|
||||
- [发送短信验证码_web端](#发送短信验证码_web端)
|
||||
- [使用短信验证码登录_web端](#使用短信验证码登录_web端)
|
||||
|
||||
---
|
||||
|
||||
web端短信登录流程:
|
||||
|
||||
1. [完成人机验证](readme.md)
|
||||
2. 发送短信,使用国际地区代码`cid`+手机号码`tel`+登录密钥`token`+极验`challenge`+验证结果`validate`+验证结果`seccode`
|
||||
3. 提交短信验证码以验证登录操作,使用国际地区代码`cid`+手机号码`tel`+短信验证码`code`
|
||||
|
||||
## 获取国际冠字码_web端
|
||||
|
||||
> https://passport.bilibili.com/web/generic/country/list
|
||||
|
||||
*请求方式:GET*
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
| ---- | ---- | -------- | ------- |
|
||||
| code | num | 返回值 | 0:成功 |
|
||||
| data | obj | 数据本体 | |
|
||||
|
||||
`data`对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
| ------ | ----- | ------------- | ---- |
|
||||
| common | array | 常用国家&地区 | |
|
||||
| others | array | 其他国家&地区 | |
|
||||
|
||||
`data`中的`common`和`others`数组:
|
||||
|
||||
| 项 | 类型 | 内容 | 备注 |
|
||||
| ---- | ---- | -------------- | ---- |
|
||||
| 0 | obj | 国家&地区1 | |
|
||||
| n | obj | 国家&地区(n+1) | |
|
||||
| …… | obj | …… | …… |
|
||||
|
||||
`common`和`others`数组中的对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
| ---------- | ---- | ------------- | ---- |
|
||||
| id | num | 国际代码值 | |
|
||||
| cname | str | 国家&地区名 | |
|
||||
| country_id | str | 国家&地区区号 | |
|
||||
|
||||
**示例:**
|
||||
|
||||
```shell
|
||||
curl 'https://passport.bilibili.com/web/generic/country/list'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"data": {
|
||||
"common": [
|
||||
{
|
||||
"id": 1,
|
||||
"cname": "中国大陆",
|
||||
"country_id": "86"
|
||||
},
|
||||
{
|
||||
"id": 5,
|
||||
"cname": "中国香港特别行政区",
|
||||
"country_id": "852"
|
||||
},
|
||||
…………
|
||||
],
|
||||
"others": [
|
||||
{
|
||||
"id": 22,
|
||||
"cname": "阿富汗",
|
||||
"country_id": "93"
|
||||
},
|
||||
{
|
||||
"id": 20,
|
||||
"cname": "阿尔巴尼亚",
|
||||
"country_id": "355"
|
||||
},
|
||||
…………
|
||||
]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
## 发送短信验证码_web端
|
||||
|
||||
> https://passport.bilibili.com/x/passport-login/web/sms/send
|
||||
|
||||
*请求方式:POST*
|
||||
|
||||
同手机号短信发送 CD 时间为 60s
|
||||
|
||||
短信验证码 timeout 为 5min
|
||||
|
||||
**正文参数 (application/x-www-form-urlencoded):**
|
||||
|
||||
| 参数名 | 类型 | 内容 | 必要性 | 备注 |
|
||||
| --- | --- | --- | --- | --- |
|
||||
| cid | num | 国际冠字码 | 必要 | 可以从[获取国际冠字码](#获取国际冠字码(web端))获取 |
|
||||
| tel | num | 手机号码 | 必要 | |
|
||||
| source | str | 登录来源 | 必要 | `main_web`:独立登录页<br />`main_mini`:小窗登录 |
|
||||
| token | str | 登录 API token | 必要 | 在[申请 captcha 验证码](readme.md#申请captcha验证码)接口处获取 |
|
||||
| challenge | str | 极验 challenge | 必要 | 在[申请 captcha 验证码](readme.md#申请captcha验证码)接口处获取 |
|
||||
| validate | str | 极验 result | 必要 | 极验验证后得到 |
|
||||
| seccode | str | 极验 result +`\|jordan` | 必要 | 极验验证后得到 |
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
| ------ | ---- | -------- | --------- |
|
||||
| code | num | 返回值 | 0:成功<br />-400:请求错误<br />1002:手机号格式错误<br />86203:短信发送次数已达上限<br />1003:验证码已经发送<br />1025:该手机号在哔哩哔哩有过永久封禁记录,无法再次注册或绑定新账号<br />2400:登录秘钥错误<br />2406:验证极验服务出错 |
|
||||
| message | str | 错误信息 | 成功为0 |
|
||||
| data | obj | 信息本体 | |
|
||||
|
||||
`data`对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
| ----------- | ---- | -------------- | ------------------------ |
|
||||
| captcha_key | str | 短信登录 token | 在下方传参时需要,请备用 |
|
||||
|
||||
**示例:**
|
||||
|
||||
例如手机号为`13888888888`,国际id为`1 (中国大陆)`,登录秘钥为`aabbccdd`,极验challenge为`2333`,极验结果为`666666`,进行发送短信验证码操作
|
||||
|
||||
```shell
|
||||
curl 'https://passport.bilibili.com/x/passport-login/web/sms/send' \
|
||||
--data-urlencode 'tel=13888888888' \
|
||||
--data-urlencode 'cid=1' \
|
||||
--data-urlencode 'source=main_web' \
|
||||
--data-urlencode 'token=aabbccdd' \
|
||||
--data-urlencode 'challenge=2333' \
|
||||
--data-urlencode 'validate=666666' \
|
||||
--data-urlencode 'seccode=666666|jordan'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{"code":0,
|
||||
"message":"0",
|
||||
"ttl":1,
|
||||
"data":{
|
||||
"captcha_key":"7542f109c3318d74847626495c68c321"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
## 使用短信验证码登录_web端
|
||||
|
||||
> https://passport.bilibili.com/x/passport-login/web/login/sms
|
||||
|
||||
*请求方式:POST*
|
||||
|
||||
验证登录成功后会进行设置以下cookie项:
|
||||
|
||||
`DedeUserID` `DedeUserID__ckMd5` `SESSDATA` `bili_jct`
|
||||
|
||||
**正文参数 (application/x-www-form-urlencoded):**
|
||||
|
||||
| 参数名 | 类型 | 内容 | 必要性 | 备注 |
|
||||
| --- | --- | --- | --- | --- |
|
||||
| cid | num | 国际冠字码 | 必要 | 可以从[获取国际冠字码](#获取国际冠字码(web端))获取 |
|
||||
| tel | num | 手机号码 | 必要 | |
|
||||
| code | num | 短信验证码 | 必要 | timeout 为 5min |
|
||||
| source | str | 登录来源 | 必要 | `main_web`:独立登录页<br />`main_mini`:小窗登录 |
|
||||
| captcha_key | str | 短信登录 token | 必要 | 从[上述API](#发送短信验证码(web端))请求成功后返回 |
|
||||
| go_url | str | 跳转url | 非必要 | 默认为 https://www.bilibili.com |
|
||||
| keep | bool | 是否记住登录 | 非必要 | `true`:记住登录<br />`false`:不记住登录 |
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
| --- | --- | --- | --- |
|
||||
| code | num | 返回值 | 0:成功<br />-400:请求错误<br />1006:请输入正确的短信验证码<br />1007:短信验证码已过期 |
|
||||
| message | str | 错误信息 | |
|
||||
| data | obj | 信息本体 | |
|
||||
|
||||
`data`对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
| --- | --- | --- | --- |
|
||||
| is_new | bool | 是否为新注册用户 | false:非新注册用户<br />true:新注册用户 |
|
||||
| status | num | 0 | 未知,可能0就是成功吧 |
|
||||
| url | str | 跳转 url | 默认为 https://www.bilibili.com |
|
||||
|
||||
**示例:**
|
||||
|
||||
使用手机号`13888888888`,短信验证码为`123456`,进行验证登录操作
|
||||
|
||||
```shell
|
||||
curl 'https://passport.bilibili.com/x/passport-login/web/login/sms'
|
||||
--data-urlencode 'cid=1' \
|
||||
--data-urlencode 'tel=13888888888' \
|
||||
--data-urlencode 'code=123456'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"data": {
|
||||
"is_new": false,
|
||||
"status": 0,
|
||||
"url": "https://space.bilibili.com"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
**响应头部抓包信息:**
|
||||
|
||||
可明显看见设置了几个cookie(填入浏览器即可成功登录)
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```http
|
||||
HTTP/1.1 200 OK
|
||||
Date: Mon, 13 Jul 2020 09:57:33 GMT
|
||||
Content-Type: application/json;charset=UTF-8
|
||||
Content-Length: 78
|
||||
Connection: keep-alive
|
||||
Server: Apache-Coyote/1.1
|
||||
Set-Cookie: DedeUserID=***; Domain=.bilibili.com; Expires=Sat, 18-Jul-2020 09:57:57 GMT; Path=/
|
||||
Set-Cookie: DedeUserID__ckMd5=***; Domain=.bilibili.com; Expires=Sat, 18-Jul-2020 09:57:57 GMT; Path=/
|
||||
Set-Cookie: SESSDATA=***; Domain=.bilibili.com; Expires=Sat, 18-Jul-2020 09:57:57 GMT; Path=/; HttpOnly
|
||||
Set-Cookie: bili_jct=***; Domain=.bilibili.com; Expires=Sat, 18-Jul-2020 09:57:57 GMT; Path=/
|
||||
Set-Cookie: sid=***; Domain=.bilibili.com; Expires=Sat, 18-Jul-2020 09:57:57 GMT; Path=/
|
||||
Expires: Mon, 13 Jul 2020 09:57:32 GMT
|
||||
Cache-Control: no-cache
|
||||
X-Cache-Webcdn: BYPASS from jd-sxhz-dx-w-01
|
||||
|
||||
```
|
||||
|
||||
</details>
|
||||
499
docs/login/login_action/password.md
Normal file
499
docs/login/login_action/password.md
Normal file
@@ -0,0 +1,499 @@
|
||||
# 密码登录
|
||||
|
||||
- [密码登录流程(伪代码)](#密码登录流程伪代码)
|
||||
- [web端密码登录](#web端密码登录)
|
||||
- [获取公钥&盐(web端)](#获取公钥&盐web端)
|
||||
- [登录操作(web端)](#登录操作web端)
|
||||
- [web端密码登录-旧版](#web端密码登录-旧版)
|
||||
- [获取公钥&盐(web端-旧版)](#获取公钥&盐web端-旧版)
|
||||
- [登录操作(web端-旧版)](#登录操作web端-旧版)
|
||||
- [APP端密码登录](#APP端密码登录)
|
||||
- [获取公钥&盐(APP端)](#获取公钥&盐APP端)
|
||||
- TODO:登录操作(APP端)
|
||||
- [登录密码的加密实例](#登录密码的加密实例)
|
||||
|
||||
---
|
||||
|
||||
## 密码登录流程(伪代码)
|
||||
|
||||
```python
|
||||
账号 = '2333333'
|
||||
密码字符串 = 'password'
|
||||
|
||||
# 1.人机验证步骤
|
||||
token, gt, challenge = 获取验证码()
|
||||
validate = 填写验证码(gt, challenge) # 这一步填写验证码 (访问极验API,得到validate)
|
||||
|
||||
# 2.密码加密步骤
|
||||
pubkey, salt = 获取公钥和盐()
|
||||
加密后的密码 = RSA公钥加密(pubkey, salt+密码字符串) # 盐需要加在密码字符串前
|
||||
base64编码后的密文 = base64编码(加密后的密码)
|
||||
|
||||
# 3.开始登录
|
||||
cookie = 密码登录(账号, base64编码后的密文, token, challenge, validate)
|
||||
存储cookie(cookie)
|
||||
SSO登录页面跳转()
|
||||
```
|
||||
|
||||
## web端密码登录
|
||||
|
||||
### 获取公钥&盐(web端)
|
||||
|
||||
> https://passport.bilibili.com/x/passport-login/web/key
|
||||
|
||||
*请求方式:GET*
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------|-----|------|------|
|
||||
| code | num | 返回值 | 0:成功 |
|
||||
| message | str | 错误信息 | |
|
||||
| ttl | num | 1 | |
|
||||
| data | obj | 信息本体 | |
|
||||
|
||||
`data`对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|------|-----|--------|------------------------------------------|
|
||||
| hash | str | 密码盐值 | 有效时间为 20s<br />恒为 16 字符<br />需要拼接在明文密码之前 |
|
||||
| key | str | rsa 公钥 | PEM 格式编码<br />加密密码时需要使用 |
|
||||
|
||||
**示例:**
|
||||
|
||||
```shell
|
||||
curl 'https://passport.bilibili.com/x/passport-login/web/key'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"message": "0",
|
||||
"ttl": 1,
|
||||
"data": {
|
||||
"hash": "9333681c87fd8d6e",
|
||||
"key": "-----BEGIN PUBLIC KEY-----\nMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDjb4V7EidX/ym28t2ybo0U6t0n\n6p4ej8VjqKHg100va6jkNbNTrLQqMCQCAYtXMXXp2Fwkk6WR+12N9zknLjf+C9sx\n/+l48mjUU8RqahiFD1XT/u2e0m2EN029OhCgkHx3Fc/KlFSIbak93EH/XlYis0w+\nXl69GV6klzgxW6d2xQIDAQAB\n-----END PUBLIC KEY-----\n"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
### 登录操作(web端)
|
||||
|
||||
> https://passport.bilibili.com/x/passport-login/web/login
|
||||
|
||||
*请求方式:POST*
|
||||
|
||||
验证登录成功后会进行设置以下 cookie 项:
|
||||
|
||||
`sid` `DedeUserID` `DedeUserID__ckMd5` `SESSDATA` `bili_jct`
|
||||
|
||||
**正文参数 (application/x-www-form-urlencoded):**
|
||||
|
||||
| 参数名 | 类型 | 内容 | 必要性 | 备注 |
|
||||
| --------- | ---- | ---------------------- | ------ | ------------------------------------------------------------ |
|
||||
| username | str | 用户登录账号 | 必要 | 手机号或邮箱地址 |
|
||||
| password | str | 加密后的带盐密码 | 必要 | base64 格式 |
|
||||
| keep | num | 0 | 必要 | |
|
||||
| token | str | 登录 token | 必要 | 在[申请 captcha 验证码](readme.md#申请captcha验证码)接口处获取 |
|
||||
| challenge | str | 极验 challenge | 必要 | 在[申请 captcha 验证码](readme.md#申请captcha验证码)接口处获取 |
|
||||
| validate | str | 极验 result | 必要 | 极验验证后得到 |
|
||||
| seccode | str | 极验 result +`\|jordan` | 必要 | 极验验证后得到 |
|
||||
| go_url | str | 跳转 url | 非必要 | 默认为 https://www.bilibili.com |
|
||||
| source | str | 登录来源 | 非必要 | `main_web`:独立登录页<br />`main_mini`:小窗登录 |
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------|-----------------------|------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| code | num | 返回值 | 0:成功<br />-105:验证码错误<br />-400:请求错误<br />-629:账号或密码错误<br />-653:用户名或密码不能为空<br />-662:提交超时,请重新提交<br />-2001:缺少必要的的参数<br />-2100:需验证手机号或邮箱<br />2400:登录秘钥错误<br />2406:验证极验服务出错<br />86000:RSA解密失败 |
|
||||
| message | str | 错误信息 | |
|
||||
| data | 成功时:obj<br />失败时:null | 数据本体 | |
|
||||
|
||||
data 对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------------|-----|-------------------|------------------------|
|
||||
| message | str | 扫码状态信息 | |
|
||||
| refresh_token | str | 刷新`refresh_token` | |
|
||||
| status | num | 0 | |
|
||||
| timestamp | num | 登录时间 | 未登录为`0`<br />时间戳 单位为毫秒 |
|
||||
| url | str | 游戏分站跨域登录 url | |
|
||||
|
||||
**示例:**
|
||||
|
||||
例如用户账号为`12345678900`,加密后的密码为`xxx`,登录秘钥为`aabbccdd`,极验challenge为`2333`,极验结果为`666666`,进行验证登录操作
|
||||
|
||||
```shell
|
||||
curl 'https://passport.bilibili.com/x/passport-login/web/login' \
|
||||
--data-urlencode 'username=12345678900' \
|
||||
--data-urlencode 'password=xxx' \
|
||||
--data-urlencode 'keep=0' \
|
||||
--data-urlencode 'source=main_web' \
|
||||
--data-urlencode 'token=aabbccdd' \
|
||||
--data-urlencode 'challenge=2333' \
|
||||
--data-urlencode 'validate=666666' \
|
||||
--data-urlencode 'seccode=666666|jordan'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"message": "0",
|
||||
"ttl": 1,
|
||||
"data": {
|
||||
"status": 0,
|
||||
"message": "",
|
||||
"url": "https://passport.biligame.com/crossDomain?DedeUserID=***&DedeUserID__ckMd5=***&Expires=***&SESSDATA=***&bili_jct=***&gourl=https%3A%2F%2Fwww.bilibili.com%2F",
|
||||
"refresh_token": "***",
|
||||
"timestamp": 1662452570273
|
||||
}
|
||||
}
|
||||
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
**响应头部抓包信息:**
|
||||
|
||||
可明显看见设置了几个 cookie
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```http
|
||||
HTTP/1.1 200 OK
|
||||
Date: Mon, 13 Jul 2020 06:56:00 GMT
|
||||
Content-Type: application/json;charset=UTF-8
|
||||
Content-Length: 273
|
||||
Connection: keep-alive
|
||||
Server: Apache-Coyote/1.1
|
||||
Set-Cookie: DedeUserID=***; Domain=.bilibili.com; Expires=Sat, 09-Jan-2021 06:39:43 GMT; Path=/
|
||||
Set-Cookie: DedeUserID__ckMd5=***; Domain=.bilibili.com; Expires=Sat, 09-Jan-2021 06:39:43 GMT; Path=/
|
||||
Set-Cookie: SESSDATA=***; Domain=.bilibili.com; Expires=Sat, 09-Jan-2021 06:39:43 GMT; Path=/; HttpOnly
|
||||
Set-Cookie: bili_jct=***; Domain=.bilibili.com; Expires=Sat, 09-Jan-2021 06:39:43 GMT; Path=/
|
||||
Content-Security-Policy-Report-Only: default-src 'self' data: *.bilibili.com *.hdslb.com; style-src 'self' 'unsafe-inline' *.hdslb.com static.geetest.com; img-src 'self' data: blob: *.bilibili.com *.hdslb.com http://*.hdslb.com static.geetest.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bilibili.com *.hdslb.com api.geetest.com static.geetest.com; object-src 'self' *.hdslb.com; media-src 'self' *.acgvideo.com http://*.acgvideo.com *.ksyungslb.com; connect-src 'self' data: wss://*.bilibili.com:* *.bilibili.com *.hdslb.com *.biliapi.net *.biliapi.com; frame-ancestors 'self' *.bilibili.com *.biligame.com; report-uri https://security.bilibili.com/csp_report
|
||||
Expires: Mon, 13 Jul 2020 06:55:59 GMT
|
||||
Cache-Control: no-cache
|
||||
X-Cache-Webcdn: BYPASS from jd-sxhz-dx-w-01
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
## web端密码登录-旧版
|
||||
|
||||
以下为密码扫码登录 API,尚可正常访问
|
||||
|
||||
### 获取公钥&盐(web端-旧版)
|
||||
|
||||
> https://passport.bilibili.com/login?act=getkey
|
||||
|
||||
*请求方式:GET*
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|------|-----|--------|------------------------------------------|
|
||||
| hash | str | 密码盐值 | 有效时间为 20s<br />恒为 16 字符<br />需要拼接在明文密码之前 |
|
||||
| key | str | rsa 公钥 | PEM 格式编码<br />加密密码时需要使用 |
|
||||
|
||||
**示例:**
|
||||
|
||||
```shell
|
||||
curl 'https://passport.bilibili.com/login?act=getkey'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"hash":"07c6501690c1af85",
|
||||
"key":"-----BEGIN PUBLIC KEY-----\nMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDjb4V7EidX/ym28t2ybo0U6t0n\n6p4ej8VjqKHg100va6jkNbNTrLQqMCQCAYtXMXXp2Fwkk6WR+12N9zknLjf+C9sx\n/+l48mjUU8RqahiFD1XT/u2e0m2EN029OhCgkHx3Fc/KlFSIbak93EH/XlYis0w+\nXl69GV6klzgxW6d2xQIDAQAB\n-----END PUBLIC KEY-----\n"
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
### 登录操作(web端-旧版)
|
||||
|
||||
|
||||
> https://passport.bilibili.com/web/login/v2
|
||||
|
||||
*请求方式:POST*
|
||||
|
||||
验证登录成功后会进行设置以下cookie项:
|
||||
|
||||
`sid` `DedeUserID` `DedeUserID__ckMd5` `SESSDATA` `bili_jct`
|
||||
|
||||
**正文参数 (application/x-www-form-urlencoded ):**
|
||||
|
||||
|
||||
| 参数名 | 类型 | 内容 | 必要性 | 备注 |
|
||||
| ----------- | ---- | ---------------------- | ------ | ------------------------------------------------------------ |
|
||||
| captchaType | num | 6 | 必要 | 必须为`6` |
|
||||
| username | str | 用户登录账号 | 必要 | 手机号或邮箱地址 |
|
||||
| password | str | 加密后的带盐密码 | 必要 | base64 格式 |
|
||||
| keep | bool | 是否记住登录 | 必要 | `true`:记住登录<br />`false`:不记住登录 |
|
||||
| key | str | 登录 token | 必要 | 在[申请 captcha 验证码](readme.md#申请captcha验证码)接口处获取 |
|
||||
| challenge | str | 极验 challenge | 必要 | 在[申请 captcha 验证码](readme.md#申请captcha验证码)接口处获取 |
|
||||
| validate | str | 极验 result | 必要 | 极验验证后得到 |
|
||||
| seccode | str | 极验 result +`\|jordan` | 必要 | 极验验证后得到 |
|
||||
|
||||
</details>
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------|-----|-------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| code | num | 返回值 | 0:成功<br />-400:请求错误<br />-629:账号或密码错误<br />-653:用户名或密码不能为空<br />-662:提交超时,请重新提交<br />-2001:缺少必要的的参数<br />-2100:需验证手机号或邮箱<br />2400:登录秘钥错误<br />2406:验证极验服务出错<br />86000:RSA解密失败 |
|
||||
| ts | num | 当前时间戳 | 成功时无此项 |
|
||||
| message | str | 错误信息 | 默认为0 |
|
||||
| data | obj | 数据本体 | 成功时有此项 |
|
||||
|
||||
`data`对象:
|
||||
|
||||
**未登录时:**
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|-------------|-----|--------------|-----|
|
||||
| redirectUrl | str | 游戏分站跨域登录 url | |
|
||||
|
||||
**已登录时:**
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|---------|------|--------------------------|-----|
|
||||
| isLogin | bool | true | |
|
||||
| goUrl | str | https://www.bilibili.com | |
|
||||
|
||||
**需验证手机号或邮箱时**
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|----------|-----|--------------------------|------------|
|
||||
| mid | num | 用户 mid | |
|
||||
| tel | str | 绑定的手机号 | 星号隐藏部分信息 |
|
||||
| email | str | 绑定的邮箱 | 星号隐藏部分信息 |
|
||||
| sorce | num | 0 | **作用尚不明确** |
|
||||
| keeptime | num | 1 | **作用尚不明确** |
|
||||
| goUrl | str | https://www.bilibili.com | |
|
||||
|
||||
**示例:**
|
||||
|
||||
例如用户账号为`12345678900`,加密后的密码为`xxx`,登录秘钥为`aabbccdd`,极验challenge为`2333`,极验结果为`666666`,进行验证登录操作
|
||||
|
||||
```shell
|
||||
curl 'https://passport.bilibili.com/web/login/v2' \
|
||||
--data-urlencode 'captchaType=6' \
|
||||
--data-urlencode 'username=12345678900' \
|
||||
--data-urlencode 'password=xxx' \
|
||||
--data-urlencode 'keep=true' \
|
||||
--data-urlencode 'token=aabbccdd' \
|
||||
--data-urlencode 'challenge=2333' \
|
||||
--data-urlencode 'validate=666666' \
|
||||
--data-urlencode 'seccode=666666|jordan'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"data": {
|
||||
"redirectUrl": "https://passport.biligame.com/crossDomain?DedeUserID=***&DedeUserID__ckMd5=***&Expires=15551000&SESSDATA=***&bili_jct=***&gourl=https%3A%2F%2Fwww.bilibili.com"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
**响应头部抓包信息:**
|
||||
|
||||
可明显看见设置了几个 cookie
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```http
|
||||
HTTP/1.1 200 OK
|
||||
Date: Mon, 13 Jul 2020 06:56:00 GMT
|
||||
Content-Type: application/json;charset=UTF-8
|
||||
Content-Length: 273
|
||||
Connection: keep-alive
|
||||
Server: Apache-Coyote/1.1
|
||||
Set-Cookie: DedeUserID=***; Domain=.bilibili.com; Expires=Sat, 09-Jan-2021 06:39:43 GMT; Path=/
|
||||
Set-Cookie: DedeUserID__ckMd5=***; Domain=.bilibili.com; Expires=Sat, 09-Jan-2021 06:39:43 GMT; Path=/
|
||||
Set-Cookie: SESSDATA=***; Domain=.bilibili.com; Expires=Sat, 09-Jan-2021 06:39:43 GMT; Path=/; HttpOnly
|
||||
Set-Cookie: bili_jct=***; Domain=.bilibili.com; Expires=Sat, 09-Jan-2021 06:39:43 GMT; Path=/
|
||||
Content-Security-Policy-Report-Only: default-src 'self' data: *.bilibili.com *.hdslb.com; style-src 'self' 'unsafe-inline' *.hdslb.com static.geetest.com; img-src 'self' data: blob: *.bilibili.com *.hdslb.com http://*.hdslb.com static.geetest.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bilibili.com *.hdslb.com api.geetest.com static.geetest.com; object-src 'self' *.hdslb.com; media-src 'self' *.acgvideo.com http://*.acgvideo.com *.ksyungslb.com; connect-src 'self' data: wss://*.bilibili.com:* *.bilibili.com *.hdslb.com *.biliapi.net *.biliapi.com; frame-ancestors 'self' *.bilibili.com *.biligame.com; report-uri https://security.bilibili.com/csp_report
|
||||
Expires: Mon, 13 Jul 2020 06:55:59 GMT
|
||||
Cache-Control: no-cache
|
||||
X-Cache-Webcdn: BYPASS from jd-sxhz-dx-w-01
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
## APP端密码登录
|
||||
|
||||
### 获取公钥&盐(APP端)
|
||||
|
||||
> http://passport.bilibili.com/api/oauth2/getKey
|
||||
|
||||
*请求方式:POST*
|
||||
|
||||
鉴权方式:appkey
|
||||
|
||||
**正文参数( application/x-www-form-urlencoded ):**
|
||||
|
||||
| 参数名 | 类型 | 内容 | 必要性 | 备注 |
|
||||
|--------|-----|-------|---------|-----|
|
||||
| appkey | str | APP密钥 | APP方式必要 | |
|
||||
| sign | str | APP签名 | APP方式必要 | |
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
|------|-----|--------|------------------------------------------|
|
||||
| hash | str | 密码盐值 | 有效时间为 20s<br />恒为 16 字符<br />需要拼接在明文密码之前 |
|
||||
| key | str | rsa 公钥 | PEM 格式编码<br />加密密码时需要使用 |
|
||||
|
||||
**示例:**
|
||||
|
||||
```shell
|
||||
curl 'https://passport.bilibili.com/api/oauth2/getKey' \
|
||||
--data-urlencode 'appkey=1d8b6e7d45233436' \
|
||||
--data-urlencode 'sign=17004c193f688f0b5665c1068e733aff'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"hash": "07c6501690c1af85",
|
||||
"key": "-----BEGIN PUBLIC KEY-----\nMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDjb4V7EidX/ym28t2ybo0U6t0n\n6p4ej8VjqKHg100va6jkNbNTrLQqMCQCAYtXMXXp2Fwkk6WR+12N9zknLjf+C9sx\n/+l48mjUU8RqahiFD1XT/u2e0m2EN029OhCgkHx3Fc/KlFSIbak93EH/XlYis0w+\nXl69GV6klzgxW6d2xQIDAQAB\n-----END PUBLIC KEY-----\n"
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
### 登录操作(APP端)
|
||||
|
||||
TODO
|
||||
|
||||
## 登录密码的加密实例
|
||||
|
||||
以下实例使用 Python 语言,在任何平台(web、APP)使用密码登录都需要如下加密步骤
|
||||
|
||||
首先在需拉取 RSA PubKey 和 salt 备用
|
||||
|
||||
```python
|
||||
import requests
|
||||
|
||||
resp = requests.get('https://passport.bilibili.com/x/passport-login/web/key').json()['data']
|
||||
print('salt =', resp['hash'])
|
||||
print('PubKey =', resp['key'])
|
||||
```
|
||||
|
||||
`hash`字段为 salt,长度固定为 16 字符,timeout 时间只有 20s
|
||||
|
||||
`key`字段为 RSA PubKey,为 PEM 格式,加密需要使用
|
||||
|
||||
```
|
||||
salt = 9773d106a67e27d6
|
||||
PubKey = -----BEGIN PUBLIC KEY-----
|
||||
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDjb4V7EidX/ym28t2ybo0U6t0n
|
||||
6p4ej8VjqKHg100va6jkNbNTrLQqMCQCAYtXMXXp2Fwkk6WR+12N9zknLjf+C9sx
|
||||
/+l48mjUU8RqahiFD1XT/u2e0m2EN029OhCgkHx3Fc/KlFSIbak93EH/XlYis0w+
|
||||
Xl69GV6klzgxW6d2xQIDAQAB
|
||||
-----END PUBLIC KEY-----
|
||||
```
|
||||
|
||||
例如登录密码为`BiShi22332323`,现在对它进行加盐并使用获取的 PubKey 加密
|
||||
|
||||
```python
|
||||
import rsa
|
||||
password = 'BiShi22332323'
|
||||
|
||||
pubKey = rsa.PublicKey.load_pkcs1_openssl_pem(resp['key']) # 读取 PEM 密钥
|
||||
encryptedPassword = rsa.encrypt((resp['hash']+password).encode(), pubKey) # 盐需要加在明文密码之前,一并加密
|
||||
print(encryptedPassword)
|
||||
```
|
||||
|
||||
下面将输出一段 bytes 数据:
|
||||
|
||||
```
|
||||
b'}\x9c\xd4\xcd\x88\x92\xa7\xde\x85\xdb\xabm\xd7\xd3\x08\x02@xo\x85\xa4\xe1\x11\xd0o\x80\x03.$\xc8l\xbe\xba;\xfe\xee\xa7(\xf8S\x95\x1e\x9106\xa4\x1d\xcf\x8e\xbe\x8d\x94A\x86s\xf9"\x12\x0c\x135\xbb\xbc\xe1\xde\x1b\x90\t)P\xeb\xa9\x8fXY]\x83\x18\x81f\n:\xdb\xe1\xbe\xe8\x1e\xba\x1c D8d}B\x17\xf9\x8a\xf0i\'1\xa5\xc4\x05&\xaa;n\xf8{\xa02\xffY\xcelU\xd5\xaf\x8aJK\xdc\xf1@\xbc\x93'
|
||||
```
|
||||
|
||||
接下来需要把加密后的结果进行 base64 编码
|
||||
|
||||
```python
|
||||
import base64
|
||||
b64Password = base64.b64encode(encryptedPassword).decode()
|
||||
print('result =', b64Password)
|
||||
```
|
||||
|
||||
以下为最终加密结果,可直接向 API 请求体传参以登录:
|
||||
|
||||
因为 RSA 公钥加密的**无法解密性**,故无法本地验证,仅可请求 API 验证(略...
|
||||
|
||||
```
|
||||
result = fZzUzYiSp96F26tt19MIAkB4b4Wk4RHQb4ADLiTIbL66O/7upyj4U5UekTA2pB3Pjr6NlEGGc/kiEgwTNbu84d4bkAkpUOupj1hZXYMYgWYKOtvhvugeuhwgRDhkfUIX+YrwaScxpcQFJqo7bvh7oDL/Wc5sVdWvikpL3PFAvJM=
|
||||
```
|
||||
|
||||
以下为密码加密的Java实现:
|
||||
|
||||
```java
|
||||
package com.ho.test;
|
||||
|
||||
import cn.hutool.core.codec.Base64;
|
||||
|
||||
import javax.crypto.Cipher;
|
||||
import java.security.KeyFactory;
|
||||
import java.security.PublicKey;
|
||||
import java.security.spec.X509EncodedKeySpec;
|
||||
|
||||
public class Test3 {
|
||||
public static void main(String[] args) throws Exception {
|
||||
//用户密码
|
||||
String password = "abcdef";
|
||||
//获取到的证书内容
|
||||
String key = "-----BEGIN PUBLIC KEY-----\nMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDjb4V7EidX/ym28t2ybo0U6t0n\n6p4ej8VjqKHg100va6jkNbNTrLQqMCQCAYtXMXXp2Fwkk6WR+12N9zknLjf+C9sx\n/+l48mjUU8RqahiFD1XT/u2e0m2EN029OhCgkHx3Fc/KlFSIbak93EH/XlYis0w+\nXl69GV6klzgxW6d2xQIDAQAB\n-----END PUBLIC KEY-----\n";
|
||||
//获取到的盐值
|
||||
String hash = "bb73382121594c46";
|
||||
String[] split = key.strip().split("\n");
|
||||
String newKey = split[1] + split[2] + split[3] + split[4];
|
||||
//进行加密
|
||||
KeyFactory keyFactory = KeyFactory.getInstance("RSA");
|
||||
X509EncodedKeySpec keySpec = new X509EncodedKeySpec(Base64.decode(newKey));
|
||||
PublicKey publicKey = keyFactory.generatePublic(keySpec);
|
||||
Cipher cipher = Cipher.getInstance(keyFactory.getAlgorithm());
|
||||
cipher.init(Cipher.PUBLIC_KEY, publicKey);
|
||||
byte[] bytes = cipher.doFinal((hash + password).getBytes());
|
||||
String encode = Base64.encode(bytes);
|
||||
System.out.println(encode);
|
||||
}
|
||||
}
|
||||
|
||||
```
|
||||
99
docs/login/login_action/readme.md
Normal file
99
docs/login/login_action/readme.md
Normal file
@@ -0,0 +1,99 @@
|
||||
# 登录操作
|
||||
|
||||
人机验证方式登录包含**账号密码登录**与手**机短信验证码登录**
|
||||
|
||||
**注:扫码登录**不需要进行**人机验证**,故**不使用**以下接口
|
||||
|
||||
## 扫码登录
|
||||
|
||||
- [扫码登录](QR.md)
|
||||
|
||||
## 验证登录
|
||||
|
||||
人机验证流程:
|
||||
|
||||
1. 请求验证码参数,得到登录密钥`key`与极验id`gt`和极验KEY`challenge`
|
||||
2. 进行滑动or点击验证
|
||||
3. 返回验证结果`validate`与`seccode`,进行短信或密码登录
|
||||
|
||||
|
||||
### 申请captcha验证码
|
||||
|
||||
> https://passport.bilibili.com/x/passport-login/captcha?source=main_web
|
||||
|
||||
*请求方式:GET*
|
||||
|
||||
**json回复:**
|
||||
|
||||
根对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
| ------ | ---- | -------- | --------- |
|
||||
| code | num | 返回值 | 0:成功 |
|
||||
| message | str | 返回信息 | |
|
||||
| ttl | num | 1 | |
|
||||
| data | obj | 信息本体 | |
|
||||
|
||||
`data`对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
| -------- | ----- | ------ | -------- |
|
||||
| geetest | obj | 极验captcha数据 | |
|
||||
| tencent | obj | (?) | **作用尚不明确** |
|
||||
| token | str | 登录 API token | 与 captcha 无关,与登录接口有关 |
|
||||
| type | str | 验证方式 | 用于判断使用哪一种验证方式,目前所见只有极验<br />geetest:极验 |
|
||||
|
||||
`geetest`对象:
|
||||
|
||||
| 字段 | 类型 | 内容 | 备注 |
|
||||
| -------- | ----- | ------ | -------- |
|
||||
| gt | str | 极验id | 一般为固定值 |
|
||||
| challenge | str | 极验KEY | 由B站后端产生用于人机验证 |
|
||||
|
||||
**示例:**
|
||||
|
||||
```shell
|
||||
curl 'https://passport.bilibili.com/x/passport-login/captcha?source=main_web'
|
||||
```
|
||||
|
||||
<details>
|
||||
<summary>查看响应示例:</summary>
|
||||
|
||||
```json
|
||||
{
|
||||
"code": 0,
|
||||
"message": "0",
|
||||
"ttl": 1,
|
||||
"data": {
|
||||
"type": "geetest",
|
||||
"token": "00fbe75cc2864ba0af969231f193a974",
|
||||
"geetest": {
|
||||
"challenge": "a57d9be17505d4a15ed84694c48fbf74",
|
||||
"gt": "ac597a4506fee079629df5d8b66dd4fe"
|
||||
},
|
||||
"tencent": {
|
||||
"appid": ""
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
### 进行验证
|
||||
|
||||
本文档为Bilibili文档,验证码为geetest极验提供,故不提供api
|
||||
|
||||
附: [手动验证器](https://kuresaru.github.io/geetest-validator/)
|
||||
[及其源码](https://github.com/kuresaru/geetest-validator)
|
||||
|
||||
1. 打开手动验证器,在1、2分别填入上面API返回的`gt`和`challenge`
|
||||
2. 点击按钮3,稍等加载验证码,点击按钮4进行验证
|
||||
3. 验证完成后,点击按钮5生成验证结果
|
||||
4. 使用最开始获得到的`key`、`challenge`和刚获得到的`validate`、`seccode`继续之后的登录操作
|
||||
|
||||
|
||||
### 继续登录
|
||||
|
||||
- [短信登录](SMS.md)
|
||||
- [密码登录](password.md)
|
||||
Reference in New Issue
Block a user