使用JMeter开展性能测试时登录遇CSRF令牌验证失败问题
Hey there, let’s tackle this CSRF token issue you’re facing—whether you’re seeing the explicit error message or just getting redirected back to the login page without a hint, the root cause is the same: your script is using a stale, recorded CSRF token instead of fetching a fresh one for each test run. Here’s how to fix it step by step:
1. Understand the Problem
Web apps use CSRF tokens to block unauthorized requests. When you record a script with BlazeMeter, it captures the token that was valid at recording time. But by the time you run the script, that token has expired or doesn’t match your current session—so the server rejects your request, either with a clear error or by sending you back to the login page to get a new token.
2. Extract the Fresh CSRF Token Dynamically
You need to pull the latest token from the page that generates it (usually the login page or the page right before your target request) using one of JMeter’s extractors:
For HTML-based tokens (most common):
- Add a CSS Selector Extractor to the request that loads the login page.
- Reference Name:
CSRF_TOKEN(or any name you like) - CSS Selector: Use the selector for your token element. For example, if it’s in a meta tag:
meta[name="csrf-token"] - Attribute:
content(since the token is stored in thecontentattribute of the meta tag)
- Reference Name:
- Or use an XPath Extractor instead:
- Reference Name:
CSRF_TOKEN - XPath Query:
//meta[@name='csrf-token']/@content
- Reference Name:
- Add a CSS Selector Extractor to the request that loads the login page.
For JSON-based tokens (if the token is returned in a JSON response):
- Add a JSON Extractor to the relevant request, then use the JSON Path expression to target the token (e.g.,
$.csrfToken).
- Add a JSON Extractor to the relevant request, then use the JSON Path expression to target the token (e.g.,
3. Inject the Extracted Token into Your Request
Now replace the static token in your target request with the dynamic variable you just created:
- If the token is a form parameter: Find the parameter in your request (e.g.,
csrfmiddlewaretoken) and set its value to${CSRF_TOKEN}. - If the token is sent in a request header: Add an HTTP Header Manager to your request, then add a header like
X-CSRF-Tokenwith the value${CSRF_TOKEN}.
4. Ensure Session Consistency
CSRF tokens are tied to your session cookie, so make sure:
- You have an HTTP Cookie Manager in your test plan (it should be added automatically when recording, but double-check it’s enabled). This keeps your session alive and ensures the token you extract matches the current session.
5. Debug if Issues Persist
If you’re still hitting problems:
- Add a View Results Tree listener to your test plan. Check the "Response Data" of the login page to confirm your extractor is correctly pulling the token.
- Compare your JMeter request with the request sent by your browser (use browser dev tools > Network tab). Make sure the token is being sent in the same place (parameter vs. header) with the same name.
- Some apps use alternative token names like
_csrforauthenticity_token—inspect the page source or browser request to find the exact name your app uses.
内容的提问来源于stack exchange,提问作者Tuba Fatima

