Symfony 6.1登录页面无限重定向循环(301)求助排查
问题排查:Symfony登录页面无限301重定向循环
此前运行正常的Symfony应用,突然出现登录页面无限301重定向循环,日志显示AccessDeniedException,以下是配置及日志信息:
security.yaml 配置
security: # https://symfony.com/doc/current/security.html#loading-the-user-the-user-provider providers: app_user_provider: entity: class: App\Entity\Users property: email firewalls: dev: pattern: ^/(_(profiler|wdt)|css|images|js)/ security: false customer: pattern: ^/customer security: false main: pattern: ^/ lazy: true provider: app_user_provider form_login: login_path: login check_path: login enable_csrf: true logout: path: logout target: /login # Easy way to control access for large sections of your site # Note: Only the *first* access control that matches will be used access_control: - { path: ^/login$, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/customer, role: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/sales, roles: [ROLE_SALES, ROLE_ADMIN] } - { path: ^/admin, role: ROLE_ADMIN }
日志信息
[2022-10-26T11:29:20.918658+00:00] request.INFO: Matched route "login". {"route":"login","route_parameters":{"_route":"login","_controller":"App\\Controller\\SecurityController::login"},"request_uri":"https://***.com/login","method":"GET"} [] [2022-10-26T11:29:20.928261+00:00] security.DEBUG: Checking for authenticator support. {"firewall_name":"main","authenticators":1} [] [2022-10-26T11:29:20.928351+00:00] security.DEBUG: Checking support on authenticator. {"firewall_name":"main","authenticator":"Symfony\\Component\\Security\\Http\\Authenticator\\FormLoginAuthenticator"} [] [2022-10-26T11:29:20.928405+00:00] security.DEBUG: Authenticator does not support the request. {"firewall_name":"main","authenticator":"Symfony\\Component\\Security\\Http\\Authenticator\\FormLoginAuthenticator"} [] [2022-10-26T11:29:20.955819+00:00] security.DEBUG: Access denied, the user is not fully authenticated; redirecting to authentication entry point. {"exception":"[object] (Symfony\\Component\\Security\\Core\\Exception\\AccessDeniedException(code: 403): Access Denied. at /vendor/symfony/security-http/Firewall/AccessListener.php:97)"} []
问题原因及解决方案
核心问题
main防火墙配置中缺少anonymous: true参数,导致未认证用户无法访问登录页面:
- 匿名用户访问
/login时,main防火墙默认拒绝未认证请求,触发AccessDeniedException - 系统自动重定向到认证入口点(即
login_path配置的/login),形成无限循环
修复步骤
在main防火墙配置中添加anonymous: true:
main: pattern: ^/ lazy: true anonymous: true # 新增该行配置 provider: app_user_provider form_login: login_path: login check_path: login enable_csrf: true logout: path: logout target: /login
额外验证点
- 确认
access_control中的^/login$规则匹配登录路由的实际路径(若路由以/login/结尾,需调整为^/login/?$) - 检查
SecurityController::login方法未添加额外权限注解(如@IsGranted),避免覆盖配置规则
内容的提问来源于stack exchange,提问作者Ben
相关产品推荐
相关产品推荐

