升级Pimcore至v11后Symfony路由加载失败求助
Pimcore 10.6.9升级至v11后的路由访问问题修复
问题概述
- 已完成Pimcore从10.6.9到v11的版本升级,
bin/console --ansi cache:clear命令可正常执行 - 访问首页
/时触发UnexpectedSessionUsageException(HTTP 500错误),错误提示:Session was used while the request was declared stateless. - 访问后台
/admin时触发AccessDeniedException - InsufficientAuthenticationException - HttpException(HTTP 401错误),错误提示:Full authentication is required to access this resource. - 当前使用Symfony 6.3.7,原
config/packages/security.yaml配置如下:
security: enable_authenticator_manager: true providers: pimcore_admin: id: Pimcore\Security\User\UserProvider firewalls: dev: pattern: ^/(_(profiler|wdt)|css|images|js)/ security: false pimcore_admin_webdav: pattern: ^/admin/asset/webdav provider: pimcore_admin http_basic: ~ pimcore_admin: pattern: ^/admin(/.*)?$ stateless: true provider: pimcore_admin login_throttling: max_attempts: 3 interval: '5 minutes' logout: path: pimcore_admin_logout target: pimcore_admin_login custom_authenticators: - Pimcore\Bundle\AdminBundle\Security\Authenticator\AdminTokenAuthenticator two_factor: auth_form_path: /admin/login/2fa # Path or route name of the two-factor form check_path: /admin/login/2fa-verify # Path or route name of the two-factor code check default_target_path: /admin # Where to redirect by default after successful authentication always_use_default_target_path: false # If it should always redirect to default_target_path auth_code_parameter_name: _auth_code # Name of the parameter for the two-factor authentication code trusted_parameter_name: _trusted # Name of the parameter for the trusted device option multi_factor: false # If ALL active two-factor methods need to be fulfilled (multi-factor authentication) access_control: # Pimcore admin ACl // DO NOT CHANGE! - { path: ^/admin/settings/display-custom-logo, roles: PUBLIC_ACCESS } - { path: ^/admin/login/2fa-verify, roles: IS_AUTHENTICATED_2FA_IN_PROGRESS} - { path: ^/admin/login/2fa, roles: IS_AUTHENTICATED_2FA_IN_PROGRESS} - { path: ^/admin/login$, roles: PUBLIC_ACCESS } - { path: ^/admin/login/(login|lostpassword|deeplink|csrf-token)$, roles: PUBLIC_ACCESS } - { path: ^/admin, roles: ROLE_PIMCORE_USER } role_hierarchy: # Pimcore admin // DO NOT CHANGE! ROLE_PIMCORE_ADMIN: [ROLE_PIMCORE_USER]
问题分析与修复方案
1. 后台/admin 401错误修复
Pimcore v11后台管理依赖会话(Session)维持登录状态及处理2FA流程,但当前配置中pimcore_admin防火墙设置了stateless: true,禁用了会话功能,导致认证流程无法正常完成。
修复操作:
修改security.yaml中pimcore_admin防火墙的stateless配置,将其设置为false或直接移除该配置(默认值为false):
pimcore_admin: pattern: ^/admin(/.*)?$ stateless: false # 移除或设置为false provider: pimcore_admin # 其他配置保持不变
2. 首页/ 500错误修复
错误提示表明请求被标记为无状态,但代码中尝试使用了会话。需确保首页对应的防火墙未启用stateless,同时配置正确的访问权限。
修复操作:
- 在
firewalls节点下添加main防火墙配置,覆盖首页路径并启用匿名访问:
main: pattern: ^/ security: true anonymous: true # 不要设置stateless: true,除非前端确实不需要会话
- 在
access_control节点添加首页的公开访问规则:
access_control: # 允许首页公开访问 - { path: ^/$, roles: PUBLIC_ACCESS } # 原有admin访问控制规则保持不变
最终生效步骤
- 保存修改后的
security.yaml文件 - 执行缓存清除命令:
bin/console cache:clear - 重启PHP-FPM或Web服务器(如Apache/Nginx)
- 重新访问
/和/admin验证修复效果
内容的提问来源于stack exchange,提问作者Lohit
相关产品推荐
相关产品推荐

