A method for accessing the interface of a dual authentication system
By entering the authentication value and adding the token value in the HTTP header, the problem of the Jmeter tool being unable to access the interface with dual authentication enabled was solved, and the interface test was successfully completed under high security.
Patent Information
- Application Number
- CN202310829988.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-07
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2043-07-07
AI Technical Summary
The account and password information corresponding to 401 cannot be entered in the Jmeter tool, resulting in the inability to access the interface with two-factor authentication enabled, causing the test to fail.
By entering the authentication value and adding the token value in the HTTP header, use the Jmeter tool to perform interface testing, including obtaining the authorization and user_token values in the browser, and setting the HTTP header manager and HTTP request parameters in the Jmeter tool.
This method achieves successful access and correct interface return value acquisition through the Jmeter tool under high security guarantee, and solves the problem that the Jmeter tool cannot input 401 information.
Smart Images

Figure CN117040790B_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the field of computer technology and relates to a method for accessing and opening a dual authentication system interface. Background Art
[0002] In HTTP, Basic authentication is a login authentication method that allows web browsers or other client programs to provide identity credentials in the form of a username and password when making a request. Web browsers all support Basic authentication, and it is commonly used in web management systems. This prompts a user to enter a username and password when accessing the system through a web page. However, when using JMeter for interface testing, the interface access fails due to an inability to interact with the page and a 401 error message is entered.
[0003] There is no account and password input option corresponding to 401 in the Jmeter tool, so failure will occur when accessing the interface with two-factor authentication enabled.
[0004] A search revealed a Chinese patent document that discloses a RESTFUL service-based IoT interface access authentication method and system [Application Number: 202111450513.9; Publication Number: CN114051042A]. In specific applications, since the difference in word vectors between the second two-end interaction topic and several first two-end interaction topics in a set mapping list does not exceed a set range, even if there is a deviation in the target IoT interaction data in the set mapping list, the association between the second two-end interaction topic and several first two-end interaction topics in the set mapping list can be used to determine a behavior description analysis record that is as accurate as possible. This makes the access security evaluation between the target IoT interaction data determined based on the behavior description analysis record and the historical IoT interaction data more accurate and reliable, thereby ensuring the accuracy of the target interaction mode stability determined based on the access security evaluation. However, the inability to interact with the page and the input of a 401 message result in an access failure to the interface. There is no account and password input option corresponding to the 401 error, so failure occurs when accessing an interface with two-factor authentication enabled.
[0005] Based on this, we propose a method to access the interface of the system with dual authentication enabled, which can complete the access to the interface with dual authentication enabled, that is, to complete the testing of the system interface through the JMeter tool under high security guarantee;
[0006] Enter the authentication value in the HTTP information header and add the token value when sending the HTTP request. In this way, the authentication will be passed when accessing the interface, the interface can be accessed directly, and the correct return value will be obtained. Summary of the Invention
[0007] The purpose of the present invention is to address the above-mentioned problems in the existing technology and propose a method for accessing the interface of a system with dual authentication enabled. The technical problem to be solved by the invention is: how to access the interface with dual authentication enabled, that is, to test the system interface through the jmeter tool under a high security guarantee, so that when accessing the interface, the authentication will be passed, the interface can be accessed directly, and the correct return value can be obtained.
[0008] The purpose of the present invention can be achieved through the following technical solutions:
[0009] A method for accessing and opening a dual authentication system interface comprises the following steps:
[0010] Step 1: Open the browser, enter the interface address, and press Enter;
[0011] Step 2: Open F12, that is, open the developer debugging tool, and obtain the value of authorization and user_token;
[0012] Step 3. In the JMeter tool, click the Thread Group. The Thread Group expands to display the following items: HttpCookie Manager, HTTP Header Manager, HTTP Request, and View Result Tree.
[0013] Step 4. In the JMeter tool, click HTTP Header Manager and add parameters: enter authorization and the value obtained in step 2;
[0014] Step 5. In the JMeter tool, click HTTP Request, add the interface address, port number, request method, and URL, and then add parameters: enter user_token and the value obtained in step 2;
[0015] Step 6. In the JMeter tool, click View Result Tree, click the HTTP Request item, and the HTTP Request-0 and HTTP Request-1 sub-items will be displayed. Click them to view them respectively.
[0016] Step 7: When accessing the interface, the authentication will be passed, and the interface can be accessed directly to obtain the correct return value.
[0017] The "authorization" typed information header in step 4 is stored in the "Name" column of the information header manager, and the authorization value typed information header is stored in the "Value" column of the information header manager. The value content is case-sensitive.
[0018] In step 5, select the "Basic" column, add the interface address, port number, request method and URL information, check the Follow algorithm and check the Use keepAlive option.
[0019] The corresponding parameters added by selecting the "Basic" column in step 5 also include: protocol type, request type, and path.
[0020] In step 5, select the "Parameter" column, type "user_token" into the "Name" column of the parameter sent with the request, and type the value of user_token into the "Value" column of the parameter sent with the request. The value content is case-sensitive.
[0021] In step 5, select the "Parameters" column, select text / plain in the "Content Type" column for the parameters sent with the request, and check the "Include equals?" column for the parameters sent with the request.
[0022] The present invention also provides a terminal device / server, comprising a processor, a memory, and a computer program / instruction stored in the memory and configured to be executed by the processor, wherein the processor implements the above-mentioned method of accessing and enabling the dual authentication system interface when executing the computer program / instruction.
[0023] The present invention also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned method of accessing and opening the dual authentication system interface.
[0024] Compared with the existing technology, this method of accessing and opening the dual authentication system interface has the following advantages:
[0025] Ability to access interfaces with dual authentication enabled, i.e., test the system interface through the JMeter tool with high security assurance;
[0026] Enter the authentication value in the HTTP information header and add the token value when sending the HTTP request. In this way, the authentication will be passed when accessing the interface, the interface can be accessed directly, and the correct return value will be obtained. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 It is a flow chart of the present invention.
[0028] Figure 2 It is a parameter diagram of the HTTP header manager in the present invention.
[0029] Figure 3 It is a schematic diagram of parameters of the HTTP request in the present invention.
[0030] Figure 4 It is a parameter diagram of the viewing result tree in the present invention.
[0031] Figure 5 It is a schematic diagram of a terminal device provided by the present invention. DETAILED DESCRIPTION
[0032] The following are specific embodiments of the present invention and the accompanying drawings to further describe the technical solutions of the present invention, but the present invention is not limited to these embodiments.
[0033] like Figures 1-4 As shown, the method for accessing and opening the dual authentication system interface includes the following steps:
[0034] Step 1: Open the browser, enter the interface address, and press Enter;
[0035] Step 2: Open F12, that is, open the developer debugging tool, and obtain the value of authorization and user_token;
[0036] Step 3. In the JMeter tool, click the Thread Group. The Thread Group expands to display the following items: HttpCookie Manager, HTTP Header Manager, HTTP Request, and View Result Tree.
[0037] Step 4. In the JMeter tool, click HTTP Header Manager and add parameters: enter authorization and the value obtained in step 2;
[0038] Step 5. In the JMeter tool, click HTTP Request, add the interface address, port number, request method, and URL, and then add parameters: enter user_token and the value obtained in step 2;
[0039] Step 6. In the JMeter tool, click View Result Tree, click the HTTP Request item, and the HTTP Request-0 and HTTP Request-1 sub-items will be displayed. Click them to view them respectively.
[0040] Step 7: When accessing the interface, the authentication will be passed, and the interface can be accessed directly to obtain the correct return value.
[0041] The "authorization" typed in step 4 is stored in the "Name" column of the Header Manager, and the value of the authorization typed in the header is stored in the "Value" column of the Header Manager. The value content is case-sensitive.
[0042] In step 5, select the "Basic" tab, add the interface address, port number, request method, and URL information, check Follow Direction, and check Use keepAlive.
[0043] The corresponding parameters added by selecting the "Basic" column in step 5 also include: protocol type, request type, and path.
[0044] In step 5, select the "Parameter" column, type "user_token" into the "Name" column of the parameter sent with the request, and type the value of user_token into the "Value" column of the parameter sent with the request. The value content is case-sensitive.
[0045] In step 5, select the "Parameters" column, select text / plain in the "Content Type" column for the parameters sent with the request, and check the "Include equals?" column for the parameters sent with the request.
[0046] like Figure 5 As shown, the present invention also provides a terminal device / server, including a processor, a memory, and a computer program / instruction stored in the memory and configured to be executed by the processor, and the processor implements the above-mentioned method of accessing and enabling the dual authentication system interface when executing the computer program / instruction.
[0047] The present invention also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned method of accessing and opening the dual authentication system interface.
[0048] Working principle of the present invention:
[0049] Step 1: Open the browser, enter the interface address, and press Enter;
[0050] Step 2: Open F12, that is, open the developer debugging tool, and obtain the value of authorization and user_token;
[0051] Step 3. In the JMeter tool, click the Thread Group. The Thread Group expands to display the following items: HttpCookie Manager, HTTP Header Manager, HTTP Request, and View Result Tree.
[0052] Step 4. In the JMeter tool, click HTTP Header Manager and add parameters: enter authorization and the value obtained in step 2. Enter "authorization" in the "Name" column of the header stored in the header manager, and enter the value of "authorization" in the "Value" column of the header stored in the header manager. The value content is case-sensitive.
[0053] Step 5. In the JMeter tool, click HTTP Request. In Step 5, select the "Basic" column, add the interface address, port number, request method, and URL information, check the Follow Calculator Direction checkbox, check the Use keepAlive checkbox, add the protocol type, request type, and path; then add parameters: enter user_token and the value obtained in Step 2, select the "Parameters" column, type "user_token" into the "Name" column of the parameter sent with the request, and type the value of user_token into the "Value" column of the parameter sent with the request. The value content is case-sensitive. Select text / plain in the "Content Type" column of the parameter sent with the request, and check the "Includes equals?" column of the parameter sent with the request.
[0054] Step 6. In the JMeter tool, click View Result Tree, click the HTTP Request item, and the HTTP Request-0 and HTTP Request-1 sub-items will be displayed. Click them to view them respectively.
[0055] Step 7: When accessing the interface, the authentication will be passed, and the interface can be accessed directly to obtain the correct return value.
[0056] In summary, the present invention can complete the access to the interface with dual authentication enabled, that is, the system interface can be tested by the jmeter tool under high security guarantee;
[0057] Enter the authentication value in the HTTP information header and add the token value when sending the HTTP request. In this way, the authentication will be passed when accessing the interface, the interface can be accessed directly, and the correct return value will be obtained.
[0058] The specific embodiments described herein are merely illustrative of the spirit of the present invention. Persons skilled in the art may make various modifications, additions, or substitutions to the described specific embodiments without departing from the spirit of the present invention or exceeding the scope of the appended claims.
Claims
1. A method for accessing and opening a dual authentication system interface, characterized in that: The following steps are involved: Step 1: Open the browser, enter the interface address, and press Enter; Step 2: Open F12, that is, open the developer debugging tool, and obtain the value of authorization and user_token; Step 3. In the JMeter tool, click the Thread Group. The Thread Group expands to display the following items: HttpCookie Manager, HTTP Header Manager, HTTP Request, and View Result Tree. Step 4. In the JMeter tool, click HTTP Header Manager and add parameters: enter authorization and the value obtained in step 2; Step 5. In the JMeter tool, click HTTP Request, select the "Basic" tab, add the interface address, port number, request method, and URL, select the "Parameters" tab, and add parameters: enter user_token and the value obtained in step 2; Step 6. In the JMeter tool, click View Result Tree, click the HTTP Request item, and the HTTP Request-0 and HTTP Request-1 sub-items will be displayed. Click them to view them respectively. Step 7: When accessing the interface, the authentication will be passed, and the interface can be accessed directly to obtain the correct return value.
2. A method for accessing and opening a dual authentication system interface according to claim 1, characterized in that: The "authorization" keyed information header in step 4 is stored in the "Name" column of the information header manager, and the authorization value keyed information header is stored in the "Value" column of the information header manager. The value content is case-sensitive.
3. A method for accessing and opening a dual authentication system interface according to claim 1, characterized in that: In step 5, select the "Basic" tab, add the interface address, port number, request method, and URL information, check Follow Direction, and check Use keepAlive.
4. A method for accessing and opening a dual authentication system interface according to claim 1, characterized in that: The corresponding parameters added by selecting the "Basic" column in step 5 also include: protocol type, request type, and path.
5. The method for accessing and opening a dual authentication system interface according to claim 1, characterized in that: In step 5, select the "Parameters" column, type "user_token" into the "Name" column of the parameter sent with the request, and type the value of user_token into the "Value" column of the parameter sent with the request. The value content is case-sensitive.
6. A method for accessing and opening a dual authentication system interface according to claim 1, characterized in that: In step 5, select the "Parameters" column, select text / plain in the "Content Type" column for the parameters sent with the request, and check the "Include equals?" column for the parameters sent with the request.
7. A terminal device, characterized in that: The system comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the method for accessing and opening a dual authentication system interface as described in any one of claims 1 to 6 is implemented.
8. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the method for accessing and opening a dual authentication system interface according to any one of claims 1 to 6.
Citation Information
Patent Citations
Internet of Things interface access authentication method and system based on RESTFUL service
CN114051042A
Automatic page element testing method and device based on Jmeter and computer terminal
CN113778861A
Jmeter-based interface automatic test method and device
CN115687156A