You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

用户未登录跳转时URL传destination参数及重定向次数过多问题求解

重定向次数过多问题解决方案

问题根因

  • 核心逻辑缺陷:登录页顶部的跳转逻辑未添加登录状态校验,只要URL携带destination参数,无论用户是否登录都会直接跳转到目标权限页;未登录状态下目标页又会重定向回带destination参数的登录页,直接形成无限重定向死循环
  • 语法错误:登录页的参数判断代码多写了一个右括号,会导致逻辑判断异常:if($_GET['destination']))
  • 次要问题:需登录页的重定向链接中?和destination之间多了多余空格,可能导致参数解析异常

修复步骤

1. 修正登录页跳转逻辑

只有用户登录成功后,才触发destination跳转,同时修复多余括号问题,可额外加白名单校验避免开放重定向漏洞,代码修改如下:

// 先校验登录状态,再处理destination跳转
if (!empty($user_id) && isset($_GET['destination'])) {
    // 配置合法的目标页面白名单,根据你的业务调整
    $allow_destinations = ['settings', 'profile', 'dashboard'];
    $destination = trim($_GET['destination']);
    if (in_array($destination, $allow_destinations)) {
        redirect(BASE_URL . '/' . $destination);
    } else {
        // 非法目标默认跳转到首页
        redirect(BASE_URL . '/index');
    }
}

2. 修正需登录页的重定向链接拼写

移除?和参数名之间的多余空格:

//LOGIN CHECK
if(empty($user_id)) {
    // 去掉?后的空格
    redirect(BASE_URL . '/login?destination=' . $page_section);
    //page section is the page type ex. Login, signup, settings
}

3. 优化redirect函数(可选)

重定向后添加exit终止后续代码执行,避免多余逻辑执行导致异常:

function redirect($destination) {
    header("Location: " . $destination);
    exit(); // 新增终止执行逻辑
}

内容的提问来源于stack exchange,提问作者user13889606

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 03:27:05