如何禁用GitLab Enterprise Server的CSRF防护以完成压测?
Hey there, let's work through this CSRF issue you're hitting while load testing GitLab Enterprise Server with JMeter. First off, I want to lead with a critical warning: disabling CSRF protection entirely is a massive security risk—it's a core defense against cross-site request forgery attacks. You should only ever consider this for an isolated, non-production test environment, and revert it immediately after your testing is done.
If you must disable CSRF protection for testing:
Here's how to configure GitLab to turn off CSRF checks:
- Open your GitLab configuration file, usually located at
/etc/gitlab/gitlab.rb - Add or update this line to set the environment variable that disables CSRF protection:
gitlab_rails['env'] = { 'GITLAB_DISABLE_CSRF_PROTECTION' => 'true' } - Save the file and apply the changes by reconfiguring GitLab:
sudo gitlab-ctl reconfigure - Restart GitLab services to ensure the setting takes effect:
sudo gitlab-ctl restart
⚠️ Critical Security Note: This disables CSRF protection across the entire GitLab instance. Never use this on a production server—it leaves your instance wide open to malicious attacks. Make sure to remove this line and reconfigure GitLab again once your load testing is finished.
Better Alternative: Fix Your JMeter Script to Use the Correct CSRF Token
Instead of disabling security measures, let's fix the root issue—capturing the right CSRF token for your requests. Here's why your current extraction might be failing, and how to fix it:
- GitLab uses separate CSRF tokens for form submissions and API/header requests. The
authenticity_tokenyou're extracting from the form is for POSTing the form itself, but theX-CSRF-Tokenheader requires a token from the page's meta tags, tied to your active session. - To capture the correct token in JMeter:
- Add a CSS Selector Extractor to the request that loads the GitLab UI page (e.g., the file upload page)
- Reference Name:
csrf_token - CSS Selector Expression:
meta[name="csrf-token"] - Attribute:
content
- Reference Name:
- In your subsequent request (the one returning 403), add a
X-CSRF-Tokenheader with the value${csrf_token} - Ensure you're maintaining the user session: Add a HTTP Cookie Manager to your test plan to persist the
_gitlab_sessioncookie—CSRF tokens are linked to the active session, so without this, your token will always be invalid.
- Add a CSS Selector Extractor to the request that loads the GitLab UI page (e.g., the file upload page)
This approach keeps GitLab's security intact while letting you run your load tests successfully.
内容的提问来源于stack exchange,提问作者Jai

