You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何禁用GitLab Enterprise Server的CSRF防护以完成压测?

Fixing CSRF 403 Errors in GitLab ES Load Testing (or Disabling CSRF Protection, with Critical Caveats)

Hey there, let's work through this CSRF issue you're hitting while load testing GitLab Enterprise Server with JMeter. First off, I want to lead with a critical warning: disabling CSRF protection entirely is a massive security risk—it's a core defense against cross-site request forgery attacks. You should only ever consider this for an isolated, non-production test environment, and revert it immediately after your testing is done.

If you must disable CSRF protection for testing:

Here's how to configure GitLab to turn off CSRF checks:

  1. Open your GitLab configuration file, usually located at /etc/gitlab/gitlab.rb
  2. Add or update this line to set the environment variable that disables CSRF protection:
    gitlab_rails['env'] = { 'GITLAB_DISABLE_CSRF_PROTECTION' => 'true' }
    
  3. Save the file and apply the changes by reconfiguring GitLab:
    sudo gitlab-ctl reconfigure
    
  4. Restart GitLab services to ensure the setting takes effect:
    sudo gitlab-ctl restart
    

⚠️ Critical Security Note: This disables CSRF protection across the entire GitLab instance. Never use this on a production server—it leaves your instance wide open to malicious attacks. Make sure to remove this line and reconfigure GitLab again once your load testing is finished.

Better Alternative: Fix Your JMeter Script to Use the Correct CSRF Token

Instead of disabling security measures, let's fix the root issue—capturing the right CSRF token for your requests. Here's why your current extraction might be failing, and how to fix it:

  • GitLab uses separate CSRF tokens for form submissions and API/header requests. The authenticity_token you're extracting from the form is for POSTing the form itself, but the X-CSRF-Token header requires a token from the page's meta tags, tied to your active session.
  • To capture the correct token in JMeter:
    • Add a CSS Selector Extractor to the request that loads the GitLab UI page (e.g., the file upload page)
      • Reference Name: csrf_token
      • CSS Selector Expression: meta[name="csrf-token"]
      • Attribute: content
    • In your subsequent request (the one returning 403), add a X-CSRF-Token header with the value ${csrf_token}
    • Ensure you're maintaining the user session: Add a HTTP Cookie Manager to your test plan to persist the _gitlab_session cookie—CSRF tokens are linked to the active session, so without this, your token will always be invalid.

This approach keeps GitLab's security intact while letting you run your load tests successfully.

内容的提问来源于stack exchange,提问作者Jai

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:23:33