You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

升级Pimcore至v11后Symfony路由加载失败求助

Pimcore 10.6.9升级至v11后的路由访问问题修复

问题概述

  • 已完成Pimcore从10.6.9到v11的版本升级,bin/console --ansi cache:clear命令可正常执行
  • 访问首页/时触发UnexpectedSessionUsageException(HTTP 500错误),错误提示:Session was used while the request was declared stateless.
  • 访问后台/admin时触发AccessDeniedException - InsufficientAuthenticationException - HttpException(HTTP 401错误),错误提示:Full authentication is required to access this resource.
  • 当前使用Symfony 6.3.7,原config/packages/security.yaml配置如下:
security:
  enable_authenticator_manager: true

  providers:
      pimcore_admin:
          id: Pimcore\Security\User\UserProvider

  firewalls:
      dev:
          pattern: ^/(_(profiler|wdt)|css|images|js)/
          security: false

      pimcore_admin_webdav:
          pattern: ^/admin/asset/webdav
          provider: pimcore_admin
          http_basic: ~

      pimcore_admin:
          pattern: ^/admin(/.*)?$
          stateless: true
          provider: pimcore_admin
          login_throttling:
              max_attempts: 3
              interval: '5 minutes'

          logout:
              path: pimcore_admin_logout
              target: pimcore_admin_login
          custom_authenticators:
              - Pimcore\Bundle\AdminBundle\Security\Authenticator\AdminTokenAuthenticator
          two_factor:
              auth_form_path: /admin/login/2fa                   # Path or route name of the two-factor form
              check_path: /admin/login/2fa-verify                # Path or route name of the two-factor code check
              default_target_path: /admin            # Where to redirect by default after successful authentication
              always_use_default_target_path: false  # If it should always redirect to default_target_path
              auth_code_parameter_name: _auth_code   # Name of the parameter for the two-factor authentication code
              trusted_parameter_name: _trusted       # Name of the parameter for the trusted device option
              multi_factor: false                    # If ALL active two-factor methods need to be fulfilled (multi-factor authentication)

  access_control:
      # Pimcore admin ACl  // DO NOT CHANGE!
      - { path: ^/admin/settings/display-custom-logo, roles: PUBLIC_ACCESS }
      - { path: ^/admin/login/2fa-verify, roles: IS_AUTHENTICATED_2FA_IN_PROGRESS}
      - { path: ^/admin/login/2fa, roles: IS_AUTHENTICATED_2FA_IN_PROGRESS}
      - { path: ^/admin/login$, roles: PUBLIC_ACCESS }
      - { path: ^/admin/login/(login|lostpassword|deeplink|csrf-token)$, roles: PUBLIC_ACCESS }
      - { path: ^/admin, roles: ROLE_PIMCORE_USER }

  role_hierarchy:
      # Pimcore admin  // DO NOT CHANGE!
      ROLE_PIMCORE_ADMIN: [ROLE_PIMCORE_USER]

问题分析与修复方案

1. 后台/admin 401错误修复

Pimcore v11后台管理依赖会话(Session)维持登录状态及处理2FA流程,但当前配置中pimcore_admin防火墙设置了stateless: true,禁用了会话功能,导致认证流程无法正常完成。

修复操作:
修改security.yaml中pimcore_admin防火墙的stateless配置,将其设置为false或直接移除该配置(默认值为false):

pimcore_admin:
    pattern: ^/admin(/.*)?$
    stateless: false  # 移除或设置为false
    provider: pimcore_admin
    # 其他配置保持不变

2. 首页/ 500错误修复

错误提示表明请求被标记为无状态,但代码中尝试使用了会话。需确保首页对应的防火墙未启用stateless,同时配置正确的访问权限。

修复操作:

  • 在firewalls节点下添加main防火墙配置,覆盖首页路径并启用匿名访问:
main:
    pattern: ^/
    security: true
    anonymous: true
    # 不要设置stateless: true,除非前端确实不需要会话
  • 在access_control节点添加首页的公开访问规则:
access_control:
    # 允许首页公开访问
    - { path: ^/$, roles: PUBLIC_ACCESS }
    # 原有admin访问控制规则保持不变

最终生效步骤

  1. 保存修改后的security.yaml文件
  2. 执行缓存清除命令:bin/console cache:clear
  3. 重启PHP-FPM或Web服务器(如Apache/Nginx)
  4. 重新访问/和/admin验证修复效果

内容的提问来源于stack exchange,提问作者Lohit

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 08:45:03