这是curl
命令:
curl -i http://xyz:3000/auth/jwt/callback -H "authorization":"Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpZCI6Imp3MkBqb2IuY29tIiwianRpIjoiNzk4NDE0ZDAtMDk5ZC00NDllLThlMjEtODkzZTVlYTJiMzdlIiwiaWF0IjoxNTMzNTQzMTkyLCJleHAiOjE1MzM1NDY3OTJ9.U9QjdilavjpsaIVnL_U769QeJNdcz9R2wY_di8X_s4c"
输出:
HTTP/1.1 302 Found
Vary: Origin, Accept, Accept-Encoding
Access-Control-Allow-Credentials: true
X-XSS-Protection: 1; mode=block
X-Frame-Options: DENY
X-Download-Options: noopen
X-Content-Type-Options: nosniff
set-cookie: access_token=s%3Az5JL8iS8v5yIEHxRynZeVmnhH3HOAVGhmiTje94G4X1yRRWrU9mLLyJGjRQemDKE.pbmbPL2t99LL5ZRTomvwf7c8%2FhJPtipBo3VnTAeiKb4; Max-Age=1209600; Path=/; Expires=Mon, 20 Aug 2018 08:15:59 GMT
set-cookie: userId=s%3A5b5961a296a6ef000ed4447c.7e%2FzUgA5l6nl%2BGECkumFMjyhrEzs5okAWaqc%2F2Mam14; Max-Age=1209600; Path=/; Expires=Mon, 20 Aug 2018 08:15:59 GMT
set-cookie: connect.sid=s%3AL06RlajA9cU8r0bsl16cnjk0TagEDtqd.VHpBhcLMNnYerLSieIfd3H%2FtscwNMwCApBlbTq0cJxo; Path=/; HttpOnly
Location: /
Content-Type: text/plain; charset=utf-8
Content-Length: 23
Date: Mon, 06 Aug 2018 08:15:59 GMT
Connection: keep-alive
这是python代码:
import requests
headers = {
'authorization': 'Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpZCI6Imp3MkBqb2IuY29tIiwianRpIjoiNzk4NDE0ZDAtMDk5ZC00NDllLThlMjEtODkzZTVlYTJiMzdlIiwiaWF0IjoxNTMzNTQzMTkyLCJleHAiOjE1MzM1NDY3OTJ9.U9QjdilavjpsaIVnL_U769QeJNdcz9R2wY_di8X_s4c ,
}
response = requests.get('http:/xyz:3000/auth/jwt/callback', headers=headers)
print(response.headers)
输出:
{'Vary': 'Origin, Accept-Encoding', 'Access-Control-Allow-Credentials': 'true', 'X-XSS-Protection': '1; mode=block', 'X-Frame-Options': 'DENY', 'X-Download-Options': 'noopen', 'X-Content-Type-Options': 'nosniff', 'Accept-Ranges': 'bytes', 'Cache-Control': 'public, max-age=0', 'Last-Modified': 'Wed, 21 Mar 2018 12:11:12 GMT', 'ETag': 'W/"12ce-16248786300"', 'Content-Type': 'text/html; charset=UTF-8', 'Content-Encoding': 'gzip', 'Date': 'Mon, 06 Aug 2018 08:34:29 GMT', 'Connection': 'keep-alive', 'Transfer-Encoding': 'chunked'}
我们可以看到,response.headers
不包含使用set-cookie
时出现的任何curl
字段。有人可以告诉我怎么回事吗?