Magento 1.9.3.3升级至1.9.3.7后后台登录失败求助
Hey there, I’ve seen this exact issue pop up for Magento 1 users post-upgrade—especially when form keys were disabled before jumping to 1.9.3.7. Let’s go through the tried-and-true fixes that have resolved this for others:
Re-enable Form Keys (this is critical!)
Magento 1.9.3.7 beefed up security around admin sessions, and even if you had form keys disabled pre-upgrade, the upgrade might have left the system in a broken state without them. Since you can’t access the admin panel, do this via your database:- Run this SQL query in your Magento database:
UPDATE core_config_data SET value = 1 WHERE path = 'admin/security/use_form_key'; - After running the query, clear the
var/sessionandvar/cachefolders on your server again to ensure old session data is gone.
- Run this SQL query in your Magento database:
Verify Admin User Status & Reset Credentials
Sometimes the upgrade process can flip user flags or cause password hash issues. Let’s check and fix that:- First, confirm your admin user is active with this query (replace
YOUR_ADMIN_USERNAMEwith your actual username):SELECT is_active FROM admin_user WHERE username = 'YOUR_ADMIN_USERNAME'; - If
is_activeis 0, update it to 1:UPDATE admin_user SET is_active = 1 WHERE username = 'YOUR_ADMIN_USERNAME'; - Try resetting your password directly via SQL too (replace
new_secure_passwordwith your desired password):UPDATE admin_user SET password = MD5('new_secure_password') WHERE username = 'YOUR_ADMIN_USERNAME';
- First, confirm your admin user is active with this query (replace
Double-Check Cookie Configuration
Even if you reset the cookie domain before, let’s confirm the settings are correct in the database:- Run this query to pull all cookie-related configs:
SELECT path, value FROM core_config_data WHERE path LIKE '%cookie%'; - Ensure
web/cookie/cookie_domainis set properly—use.yourdomain.com(with the leading dot) if you have subdomains, or justyourdomain.comif you don’t. - Make sure
web/cookie/cookie_pathis set to/(this is the default and prevents session issues).
- Run this query to pull all cookie-related configs:
Fix File Permissions
Upgrade scripts can sometimes mess up file permissions, which breaks session handling:- Ensure the
var/session,var/cache, andvar/tmpfolders are writable by your web server (usually permissions of 755 work, but 777 might be needed depending on your host setup). - Check that
app/etc/local.xmlhas permissions set to 644—world-writable permissions here can cause security-related session issues.
- Ensure the
Disable Custom Extensions Temporarily
A conflicting extension might be breaking the admin login flow after the upgrade:- Rename the
app/etc/modulesfolder toapp/etc/modules_disabledto turn off all custom extensions. - Clear your server’s cache and session folders, then try logging in again. If this works, re-enable extensions one by one to find which one is causing the problem.
- Rename the
Quick Tip: If none of these fixes work, check your server’s error logs (look in
/var/log/apache2/or/var/log/nginx/for web server logs, andvar/reportin your Magento directory) for more detailed error messages. The generic login error hides a lot of specific issues, and the logs will often point you right to the problem.
内容的提问来源于stack exchange,提问作者Vic

