PHPUnit + Symfony:登录测试时出现循环跳转问题
Hey there! Let’s figure out why your login form keeps redirecting back to /login even when you’re using correct credentials and a working submit button. I’ve run into this exact issue with Symfony 4 and FOSUserBundle 2.x, so here are the most common fixes to try:
1. Double-Check Your Firewall Configuration (security.yaml)
First, make sure your firewall settings are properly set up for FOSUserBundle. The check_path needs to be within the firewall’s scope, and anonymous access should be allowed for the login page. Here’s a working example snippet:
security: providers: fos_userbundle: id: fos_user.user_provider.username_email firewalls: main: pattern: ^/ anonymous: true form_login: provider: fos_userbundle login_path: fos_user_security_login check_path: fos_user_security_check csrf_token_generator: security.csrf.token_manager logout: path: fos_user_security_logout
If you’ve customized your login route, ensure the check_path matches the route name (or path) you’re using, and that it accepts POST requests.
2. Verify CSRF Token is Being Passed
FOSUserBundle requires a valid CSRF token for login requests. If your template isn’t including it, Symfony will silently reject the login and redirect you back. Make sure your login form includes:
- Either
{{ form_widget(form._token) }}to render the token field explicitly - Or
{{ form_end(form) }}at the end of your form (this automatically renders the token and closing tags)
You can double-check in your browser’s dev tools (Network tab) — when you submit the form, look for the _csrf_token parameter in the POST payload. If it’s missing or invalid, that’s the culprit.
3. Check Your User’s Account Status
FOSUserBundle users have an enabled flag by default. If your test user is disabled (even if credentials are correct), the system will redirect you back to the login page without an error message.
You can verify this via the command line:
php bin/console fos:user:show your_username_here
Look for the Enabled field — if it’s no, enable the user with:
php bin/console fos:user:enable your_username_here
4. Confirm User Provider Setup
Ensure your security configuration is using the FOSUserBundle user provider. In security.yaml, the providers section should reference fos_userbundle as shown in step 1. If you’re using a custom user provider, make sure it correctly retrieves users and validates passwords against FOSUserBundle’s encoding setup.
5. Check for Route Conflicts
Sometimes custom routes can override FOSUserBundle’s default /login route. Run this command to list all registered routes:
php bin/console debug:router
Look for fos_user_security_login — confirm its path is /login (or whatever you expect) and that no other route is overriding it.
6. Dig Into Security Logs
If none of the above fixes work, enable Symfony’s security logs to get a detailed error message. In config/packages/dev/monolog.yaml, add a dedicated security handler:
monolog: handlers: # ... keep your existing handlers security: type: stream path: "%kernel.logs_dir%/security.log" level: debug channels: [security]
After submitting the login form again, check var/log/security.log — it will tell you exactly why the login failed (e.g., "User account is disabled", "Invalid CSRF token", or "Bad credentials").
内容的提问来源于stack exchange,提问作者Mathieu Thiry

