Validate data integrity under load
Hard120 pts~45 min
- Data integrity
- Session isolation
Practice app · Checkout Service
A load-testable checkout service with realistic latency that degrades under concurrency, plus a live metrics view.
Your starter code already declares BASE_URL — call the API relative to it.
Objective
Verify that concurrent sessions stay isolated and every response carries correct data.
Your task
- 1Set options { vus: 5, iterations: 20 }.
- 2Each iteration: login, then POST /perf/cart with the session's token + csrf → check 200 and a non-empty cartId.
- 3Send a second cart request with a wrong X-CSRF-Token → check 403 and error.code CSRF_MISMATCH.
- 4GET BASE_URL + "/perf/checkout" → check status "confirmed" and a non-empty orderId.
Acceptance criteria
- Login, cart and checkout return 200
- The CSRF header is sent
- At least 60 check() calls pass
k6 load testing · Performance Testing · Assertions & validation