You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JMeter录制登录脚本后因__RequestVerificationToken无法登录求助

Troubleshooting __RequestVerificationToken Extraction in JMeter

Hey there, let's dig into why your CSRF token extraction isn't working—this is a super common pain point with ASP.NET (and similar) apps, so I’ve got a few tried-and-true fixes to walk you through.

1. First, confirm the token’s exact HTML structure

Before tweaking your regex, double-check the actual response from your login page using the View Results Tree listener. Search for __RequestVerificationToken and look at its full HTML snippet. For example:

<input type="hidden" name="__RequestVerificationToken" value="XyZ123+/abc=" />

Common mismatches here include:

  • Attribute order (e.g., type comes before name, which breaks regex that expects name first)
  • Single quotes instead of double quotes around attribute values
  • Extra whitespace or closing tag variations (like > instead of />)

2. Refine your regular expression

Your existing patterns are close, but let’s make them more robust:

  • Instead of relying on strict tag structure, use a flexible regex that ignores attribute order:
    name="__RequestVerificationToken".*?value="([^"]+)"
    
    The [^"]+ part safely captures everything until the next double quote, avoiding issues with special characters like + or / in the token.
  • Double-check your Regular Expression Extractor settings:
    • Template: Make sure it’s set to $1$ (captures the first group)
    • Match No.: Use 1 to grab the first occurrence of the token
    • Default Value: Set something like TOKEN_NOT_FOUND—this makes it easy to spot if extraction failed in the Debug Sampler

3. Verify the extractor’s scope

Ensure your Regular Expression Extractor is directly attached as a child to the request that returns the login page (not the login submission request!). If the extractor is in the wrong scope, it won’t process the correct response.

4. Try a CSS/JQuery Extractor instead of regex

Regex can be finicky with HTML—for more reliable extraction, use a CSS/JQuery Extractor instead:

  • Set Reference Name to __RequestVerificationToken
  • Set CSS/JQuery Expression to input[name='__RequestVerificationToken']
  • Set Attribute to value

This method targets the HTML element directly, so it doesn’t care about attribute order or minor markup variations.

5. Debug to rule out other issues

  • Add a Debug Sampler after your extraction step and run the test—check if the __RequestVerificationToken variable has a valid value. If it’s showing your default value, extraction failed; if it has a token, the problem might be in how you’re passing it to the login request (e.g., typos in the form parameter name).
  • Use the Regular Expression Tester in the View Results Tree to paste your response and test your regex in real time—this is the fastest way to validate if your pattern works.

内容的提问来源于stack exchange,提问作者Lakshmikanth

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:00:49