You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用JMeter开展性能测试时登录遇CSRF令牌验证失败问题

Fixing "CSRF token validation failed" in JMeter (BlazeMeter Recorded Scripts)

Hey there, let’s tackle this CSRF token issue you’re facing—whether you’re seeing the explicit error message or just getting redirected back to the login page without a hint, the root cause is the same: your script is using a stale, recorded CSRF token instead of fetching a fresh one for each test run. Here’s how to fix it step by step:

1. Understand the Problem

Web apps use CSRF tokens to block unauthorized requests. When you record a script with BlazeMeter, it captures the token that was valid at recording time. But by the time you run the script, that token has expired or doesn’t match your current session—so the server rejects your request, either with a clear error or by sending you back to the login page to get a new token.

2. Extract the Fresh CSRF Token Dynamically

You need to pull the latest token from the page that generates it (usually the login page or the page right before your target request) using one of JMeter’s extractors:

  • For HTML-based tokens (most common):

    • Add a CSS Selector Extractor to the request that loads the login page.
      • Reference Name: CSRF_TOKEN (or any name you like)
      • CSS Selector: Use the selector for your token element. For example, if it’s in a meta tag: meta[name="csrf-token"]
      • Attribute: content (since the token is stored in the content attribute of the meta tag)
    • Or use an XPath Extractor instead:
      • Reference Name: CSRF_TOKEN
      • XPath Query: //meta[@name='csrf-token']/@content
  • For JSON-based tokens (if the token is returned in a JSON response):

    • Add a JSON Extractor to the relevant request, then use the JSON Path expression to target the token (e.g., $.csrfToken).

3. Inject the Extracted Token into Your Request

Now replace the static token in your target request with the dynamic variable you just created:

  • If the token is a form parameter: Find the parameter in your request (e.g., csrfmiddlewaretoken) and set its value to ${CSRF_TOKEN}.
  • If the token is sent in a request header: Add an HTTP Header Manager to your request, then add a header like X-CSRF-Token with the value ${CSRF_TOKEN}.

4. Ensure Session Consistency

CSRF tokens are tied to your session cookie, so make sure:

  • You have an HTTP Cookie Manager in your test plan (it should be added automatically when recording, but double-check it’s enabled). This keeps your session alive and ensures the token you extract matches the current session.

5. Debug if Issues Persist

If you’re still hitting problems:

  • Add a View Results Tree listener to your test plan. Check the "Response Data" of the login page to confirm your extractor is correctly pulling the token.
  • Compare your JMeter request with the request sent by your browser (use browser dev tools > Network tab). Make sure the token is being sent in the same place (parameter vs. header) with the same name.
  • Some apps use alternative token names like _csrf or authenticity_token—inspect the page source or browser request to find the exact name your app uses.

内容的提问来源于stack exchange,提问作者Tuba Fatima

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 07:32:14