JMeter录制登录脚本后因__RequestVerificationToken无法登录求助
Hey there, let's dig into why your CSRF token extraction isn't working—this is a super common pain point with ASP.NET (and similar) apps, so I’ve got a few tried-and-true fixes to walk you through.
1. First, confirm the token’s exact HTML structure
Before tweaking your regex, double-check the actual response from your login page using the View Results Tree listener. Search for __RequestVerificationToken and look at its full HTML snippet. For example:
<input type="hidden" name="__RequestVerificationToken" value="XyZ123+/abc=" />
Common mismatches here include:
- Attribute order (e.g.,
typecomes beforename, which breaks regex that expectsnamefirst) - Single quotes instead of double quotes around attribute values
- Extra whitespace or closing tag variations (like
>instead of/>)
2. Refine your regular expression
Your existing patterns are close, but let’s make them more robust:
- Instead of relying on strict tag structure, use a flexible regex that ignores attribute order:
Thename="__RequestVerificationToken".*?value="([^"]+)"[^"]+part safely captures everything until the next double quote, avoiding issues with special characters like+or/in the token. - Double-check your Regular Expression Extractor settings:
- Template: Make sure it’s set to
$1$(captures the first group) - Match No.: Use
1to grab the first occurrence of the token - Default Value: Set something like
TOKEN_NOT_FOUND—this makes it easy to spot if extraction failed in the Debug Sampler
- Template: Make sure it’s set to
3. Verify the extractor’s scope
Ensure your Regular Expression Extractor is directly attached as a child to the request that returns the login page (not the login submission request!). If the extractor is in the wrong scope, it won’t process the correct response.
4. Try a CSS/JQuery Extractor instead of regex
Regex can be finicky with HTML—for more reliable extraction, use a CSS/JQuery Extractor instead:
- Set Reference Name to
__RequestVerificationToken - Set CSS/JQuery Expression to
input[name='__RequestVerificationToken'] - Set Attribute to
value
This method targets the HTML element directly, so it doesn’t care about attribute order or minor markup variations.
5. Debug to rule out other issues
- Add a Debug Sampler after your extraction step and run the test—check if the
__RequestVerificationTokenvariable has a valid value. If it’s showing your default value, extraction failed; if it has a token, the problem might be in how you’re passing it to the login request (e.g., typos in the form parameter name). - Use the Regular Expression Tester in the View Results Tree to paste your response and test your regex in real time—this is the fastest way to validate if your pattern works.
内容的提问来源于stack exchange,提问作者Lakshmikanth

