A method for accessing the interface of a dual authentication system

By entering the authentication value and adding the token value in the HTTP header, the problem of the Jmeter tool being unable to access the interface with dual authentication enabled was solved, and the interface test was successfully completed under high security.

CN117040790BActive Publication Date: 2025-09-09北京中睿天下信息技术有限公司
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310829988.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-07
Publication Date
2025-09-09
Estimated Expiration
2043-07-07

AI Technical Summary

Technical Problem

The account and password information corresponding to 401 cannot be entered in the Jmeter tool, resulting in the inability to access the interface with two-factor authentication enabled, causing the test to fail.

Method used

By entering the authentication value and adding the token value in the HTTP header, use the Jmeter tool to perform interface testing, including obtaining the authorization and user_token values ​​in the browser, and setting the HTTP header manager and HTTP request parameters in the Jmeter tool.

Benefits of technology

This method achieves successful access and correct interface return value acquisition through the Jmeter tool under high security guarantee, and solves the problem that the Jmeter tool cannot input 401 information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117040790B_ABST
    Figure CN117040790B_ABST
Patent Text Reader

Abstract

The present invention provides a method for accessing a dual-authentication system interface, belonging to the field of computer technology. The method solves the problem that the Jmeter tool cannot interact with a page and input a 401 message, resulting in failure when accessing an interface with dual-authentication enabled. The method comprises the following steps: opening a browser and inputting an interface address; pressing F12 to obtain the authorization value and the user_token value; clicking a thread group in the Jmeter tool; using the HTTP header manager, adding the authorization parameter and value; making an HTTP request, adding the interface address, port number, request method, and URL, and then adding the user_token parameter and value; viewing the result tree; and when accessing the interface, authentication is passed, and the interface can be directly accessed to obtain a correct return value. The present invention can access an interface with dual-authentication enabled and test the system interface using the Jmeter tool. The authentication value is inputted into the HTTP header, and the token value is added when sending the HTTP request. When accessing the interface, authentication is passed, and a correct return value is obtained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the field of computer technology and relates to a method for accessing and opening a dual authentication system interface. Background Art

[0002] In HTTP, Basic authentication is a login authentication method that allows web browsers or other client programs to provide identity credentials in the form of a username and password when making a request. Web browsers all support Basic authentication, and it is commonly used in web management systems. This prompts a user to enter a username and password when accessing the system through a web page. However, when using JMeter for interface testing, the interface access fails due to an inability to interact with the page and a 401 error message is entered.

[0003] There is no account and password input option corresponding to 401 in the Jmeter tool, so failure will occur when accessing the interface with two-factor authentication enabled.

[0004] A search revealed a Chinese patent document that discloses a RESTFUL service-based IoT interface access authentication method and system [Application Number: 202111450513.9; Publication Number: CN114051042A]. In specific applications, since the difference in word vectors between the second two-end interaction topic and several first two-end interaction topics in a set mapping list does not exceed a set range, even if there is a deviation in the target IoT interaction data in the set mapping list, the association between the second two-end interaction topic and several first two-end interaction topics in the set mapping list can be used to determine a behavior description analysis record that is as accurate as possible. This makes the access security evaluation between the target IoT interaction data determined based on the behavior description analysis record and the historical IoT interaction data more accurate and reliable, thereby ensuring the accuracy of the target interaction mode stability determined based on the access security evaluation. However, the inability to interact with the page and the input of a 401 message result in an access failure to the interface. There is no account and password input option corresponding to the 401 error, so failure occurs when accessing an interface with two-factor authentication enabled.

[0005] Based on this, we propose a method to access the interface of the system with dual authentication enabled, which can complete the access to the interface with dual authentication enabled, that is, to complete the testing of the system interface through the JMeter tool under high security guarantee;

[0006] Enter the authentication value in the HTTP information header and add the token value when sending the HTTP request. In this way, the authentication will be passed when accessing the interface, the interface can be accessed directly, and the correct return value will be obtained. Summary of the Invention

[0007] The purpose of the present invention is to address the above-mentioned problems in the existing technology and propose a method for accessing the interface of a system with dual authentication enabled. The technical problem to be solved by the invention is: how to access the interface with dual authentication enabled, that is, to test the system interface through the jmeter tool under a high security guarantee, so that when accessing the interface, the authentication will be passed, the interface can be accessed directly, and the correct return value can be obtained.

[0008] The purpose of the present invention can be achieved through the following technical solutions:

[0009] A method for accessing and opening a dual authentication system interface comprises the following steps:

[0010] Step 1: Open the browser, enter the interface address, and press Enter;

[0011] Step 2: Open F12, that is, open the developer debugging tool, and obtain the value of authorization and user_token;

[0012] Step 3. In the JMeter tool, click the Thread Group. The Thread Group expands to display the following items: HttpCookie Manager, HTTP Header Manager, HTTP Request, and View Result Tree.

[0013] Step 4. In the JMeter tool, click HTTP Header Manager and add parameters: enter authorization and the value obtained in step 2;

[0014] Step 5. In the JMeter tool, click HTTP Request, add the interface address, port number, request method, and URL, and then add parameters: enter user_token and the value obtained in step 2;

[0015] Step 6. In the JMeter tool, click View Result Tree, click the HTTP Request item, and the HTTP Request-0 and HTTP Request-1 sub-items will be displayed. Click them to view them respectively.

[0016] Step 7: When accessing the interface, the authentication will be passed, and the interface can be accessed directly to obtain the correct return value.

[0017] The "authorization" typed information header in step 4 is stored in the "Name" column of the information header manager, and the authorization value typed information header is stored in the "Value" column of the information header manager. The value content is case-sensitive.

[0018] In step 5, select the "Basic" column, add the interface address, port number, request method and URL information, check the Follow algorithm and check the Use keepAlive option.

[0019] The corresponding parameters added by selecting the "Basic" column in step 5 also include: protocol type, request type, and path.

[0020] In step 5, select the "Parameter" column, type "user_token" into the "Name" column of the parameter sent with the request, and type the value of user_token into the "Value" column of the parameter sent with the request. The value content is case-sensitive.

[0021] In step 5, select the "Parameters" column, select text / plain in the "Content Type" column for the parameters sent with the request, and check the "Include equals?" column for the parameters sent with the request.

[0022] The present invention also provides a terminal device / server, comprising a processor, a memory, and a computer program / instruction stored in the memory and configured to be executed by the processor, wherein the processor implements the above-mentioned method of accessing and enabling the dual authentication system interface when executing the computer program / instruction.

[0023] The present invention also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned method of accessing and opening the dual authentication system interface.

[0024] Compared with the existing technology, this method of accessing and opening the dual authentication system interface has the following advantages:

[0025] Ability to access interfaces with dual authentication enabled, i.e., test the system interface through the JMeter tool with high security assurance;

[0026] Enter the authentication value in the HTTP information header and add the token value when sending the HTTP request. In this way, the authentication will be passed when accessing the interface, the interface can be accessed directly, and the correct return value will be obtained. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 It is a flow chart of the present invention.

[0028] Figure 2 It is a parameter diagram of the HTTP header manager in the present invention.

[0029] Figure 3 It is a schematic diagram of parameters of the HTTP request in the present invention.

[0030] Figure 4 It is a parameter diagram of the viewing result tree in the present invention.

[0031] Figure 5 It is a schematic diagram of a terminal device provided by the present invention. DETAILED DESCRIPTION

[0032] The following are specific embodiments of the present invention and the accompanying drawings to further describe the technical solutions of the present invention, but the present invention is not limited to these embodiments.

[0033] like Figures 1-4 As shown, the method for accessing and opening the dual authentication system interface includes the following steps:

[0034] Step 1: Open the browser, enter the interface address, and press Enter;

[0035] Step 2: Open F12, that is, open the developer debugging tool, and obtain the value of authorization and user_token;

[0036] Step 3. In the JMeter tool, click the Thread Group. The Thread Group expands to display the following items: HttpCookie Manager, HTTP Header Manager, HTTP Request, and View Result Tree.

[0037] Step 4. In the JMeter tool, click HTTP Header Manager and add parameters: enter authorization and the value obtained in step 2;

[0038] Step 5. In the JMeter tool, click HTTP Request, add the interface address, port number, request method, and URL, and then add parameters: enter user_token and the value obtained in step 2;

[0039] Step 6. In the JMeter tool, click View Result Tree, click the HTTP Request item, and the HTTP Request-0 and HTTP Request-1 sub-items will be displayed. Click them to view them respectively.

[0040] Step 7: When accessing the interface, the authentication will be passed, and the interface can be accessed directly to obtain the correct return value.

[0041] The "authorization" typed in step 4 is stored in the "Name" column of the Header Manager, and the value of the authorization typed in the header is stored in the "Value" column of the Header Manager. The value content is case-sensitive.

[0042] In step 5, select the "Basic" tab, add the interface address, port number, request method, and URL information, check Follow Direction, and check Use keepAlive.

[0043] The corresponding parameters added by selecting the "Basic" column in step 5 also include: protocol type, request type, and path.

[0044] In step 5, select the "Parameter" column, type "user_token" into the "Name" column of the parameter sent with the request, and type the value of user_token into the "Value" column of the parameter sent with the request. The value content is case-sensitive.

[0045] In step 5, select the "Parameters" column, select text / plain in the "Content Type" column for the parameters sent with the request, and check the "Include equals?" column for the parameters sent with the request.

[0046] like Figure 5 As shown, the present invention also provides a terminal device / server, including a processor, a memory, and a computer program / instruction stored in the memory and configured to be executed by the processor, and the processor implements the above-mentioned method of accessing and enabling the dual authentication system interface when executing the computer program / instruction.

[0047] The present invention also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned method of accessing and opening the dual authentication system interface.

[0048] Working principle of the present invention:

[0049] Step 1: Open the browser, enter the interface address, and press Enter;

[0050] Step 2: Open F12, that is, open the developer debugging tool, and obtain the value of authorization and user_token;

[0051] Step 3. In the JMeter tool, click the Thread Group. The Thread Group expands to display the following items: HttpCookie Manager, HTTP Header Manager, HTTP Request, and View Result Tree.

[0052] Step 4. In the JMeter tool, click HTTP Header Manager and add parameters: enter authorization and the value obtained in step 2. Enter "authorization" in the "Name" column of the header stored in the header manager, and enter the value of "authorization" in the "Value" column of the header stored in the header manager. The value content is case-sensitive.

[0053] Step 5. In the JMeter tool, click HTTP Request. In Step 5, select the "Basic" column, add the interface address, port number, request method, and URL information, check the Follow Calculator Direction checkbox, check the Use keepAlive checkbox, add the protocol type, request type, and path; then add parameters: enter user_token and the value obtained in Step 2, select the "Parameters" column, type "user_token" into the "Name" column of the parameter sent with the request, and type the value of user_token into the "Value" column of the parameter sent with the request. The value content is case-sensitive. Select text / plain in the "Content Type" column of the parameter sent with the request, and check the "Includes equals?" column of the parameter sent with the request.

[0054] Step 6. In the JMeter tool, click View Result Tree, click the HTTP Request item, and the HTTP Request-0 and HTTP Request-1 sub-items will be displayed. Click them to view them respectively.

[0055] Step 7: When accessing the interface, the authentication will be passed, and the interface can be accessed directly to obtain the correct return value.

[0056] In summary, the present invention can complete the access to the interface with dual authentication enabled, that is, the system interface can be tested by the jmeter tool under high security guarantee;

[0057] Enter the authentication value in the HTTP information header and add the token value when sending the HTTP request. In this way, the authentication will be passed when accessing the interface, the interface can be accessed directly, and the correct return value will be obtained.

[0058] The specific embodiments described herein are merely illustrative of the spirit of the present invention. Persons skilled in the art may make various modifications, additions, or substitutions to the described specific embodiments without departing from the spirit of the present invention or exceeding the scope of the appended claims.

Claims

1. A method for accessing and opening a dual authentication system interface, characterized in that: The following steps are involved: Step 1: Open the browser, enter the interface address, and press Enter; Step 2: Open F12, that is, open the developer debugging tool, and obtain the value of authorization and user_token; Step 3. In the JMeter tool, click the Thread Group. The Thread Group expands to display the following items: HttpCookie Manager, HTTP Header Manager, HTTP Request, and View Result Tree. Step 4. In the JMeter tool, click HTTP Header Manager and add parameters: enter authorization and the value obtained in step 2; Step 5. In the JMeter tool, click HTTP Request, select the "Basic" tab, add the interface address, port number, request method, and URL, select the "Parameters" tab, and add parameters: enter user_token and the value obtained in step 2; Step 6. In the JMeter tool, click View Result Tree, click the HTTP Request item, and the HTTP Request-0 and HTTP Request-1 sub-items will be displayed. Click them to view them respectively. Step 7: When accessing the interface, the authentication will be passed, and the interface can be accessed directly to obtain the correct return value.

2. A method for accessing and opening a dual authentication system interface according to claim 1, characterized in that: The "authorization" keyed information header in step 4 is stored in the "Name" column of the information header manager, and the authorization value keyed information header is stored in the "Value" column of the information header manager. The value content is case-sensitive.

3. A method for accessing and opening a dual authentication system interface according to claim 1, characterized in that: In step 5, select the "Basic" tab, add the interface address, port number, request method, and URL information, check Follow Direction, and check Use keepAlive.

4. A method for accessing and opening a dual authentication system interface according to claim 1, characterized in that: The corresponding parameters added by selecting the "Basic" column in step 5 also include: protocol type, request type, and path.

5. The method for accessing and opening a dual authentication system interface according to claim 1, characterized in that: In step 5, select the "Parameters" column, type "user_token" into the "Name" column of the parameter sent with the request, and type the value of user_token into the "Value" column of the parameter sent with the request. The value content is case-sensitive.

6. A method for accessing and opening a dual authentication system interface according to claim 1, characterized in that: In step 5, select the "Parameters" column, select text / plain in the "Content Type" column for the parameters sent with the request, and check the "Include equals?" column for the parameters sent with the request.

7. A terminal device, characterized in that: The system comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the method for accessing and opening a dual authentication system interface as described in any one of claims 1 to 6 is implemented.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the method for accessing and opening a dual authentication system interface according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Internet of Things interface access authentication method and system based on RESTFUL service

    CN114051042A

  • Automatic page element testing method and device based on Jmeter and computer terminal

    CN113778861A

  • Jmeter-based interface automatic test method and device

    CN115687156A