Correlate a dynamic token
Hard120 pts~45 min
- Correlation
- Dynamic values
Practice app · Checkout Service
A load-testable checkout service with realistic latency that degrades under concurrency, plus a live metrics view.
Your starter code already declares BASE_URL — call the API relative to it.
Objective
Extract the session token and CSRF value from login and send them on the next request.
Your task
- 1POST BASE_URL + "/perf/login" with JSON.stringify({ username: "qa@target.dev", password: "Test@123" }) with Content-Type: application/json.
- 2const { token, csrf } = res.json().
- 3POST BASE_URL + "/perf/cart" with { sku: "TQA-200", qty: 2 } and headers Authorization: Bearer <token>, X-CSRF-Token: <csrf>, Content-Type: application/json.
- 4check the cart returns 200 with a cartId. Use { vus: 3, iterations: 9 }.
Acceptance criteria
- POST /perf/login returns 200
- POST /perf/cart returns 200
- The X-CSRF-Token header is sent
- At least 9 check() calls pass
k6 load testing · Performance Testing · Scripting basics