FOSUserBundle密码重置请求跳转至登录页问题排查(附配置)
Hey there, let's figure out why clicking your password reset button (linked to the fos_user_resetting_request route) is sending you to the login page instead of the reset request form. Here are the most common fixes to check step by step:
1. Verify Firewall Access Control Rules
This is the #1 culprit for this issue. FOSUserBundle's password reset routes need to be accessible to anonymous users—if your security config requires authentication for the reset path, it'll automatically redirect to the login page.
Open your security.yml and check the access_control section. Make sure you have a rule that allows anonymous access to the resetting routes:
security: # ... other existing config access_control: # Allow anonymous access to password reset pages - { path: ^/resetting, roles: IS_AUTHENTICATED_ANONYMOUSLY } # Keep your other rules below (e.g., login, admin routes) - { path: ^/login$, roles: IS_AUTHENTICATED_ANONYMOUSLY } - { path: ^/admin, roles: ROLE_ADMIN }
Double-check that the path matches the actual URL prefix for your reset routes (you can confirm this with php bin/console debug:router fos_user_resetting_request to see the full path).
2. Confirm Firewall Name Match
In your config.yml, you've set firewall_name: main for FOSUserBundle. Ensure that your security.yml has a main firewall defined, and that its pattern covers the reset route's path. For example:
security: firewalls: main: pattern: ^/ # ... other firewall settings (form_login, logout, etc.) fos_user: true
If the main firewall's pattern doesn't include the reset path, FOSUserBundle might not apply its default access rules correctly.
3. Fix Template Syntax Error
Looking at your button code, there's an unclosed Twig expression:
<a href="{{ path('fos_user_resetting_request') }}" class="__input __button">{{ 'resetting...`
You need to close the {{ }} block properly, like:
<a href="{{ path('fos_user_resetting_request') }}" class="__input __button">{{ 'resetting.password'|trans }}</a>
While this might not directly cause the redirect, a broken template could lead to unexpected behavior—fixing it ensures you're generating the correct route link.
4. Ensure Password Resetting is Enabled
By default, FOSUserBundle enables password resetting, but it's worth confirming in your config.yml that there's no disabled setting. Add or check the resetting block if it's missing:
fos_user: # ... existing config resetting: enabled: true token_ttl: 86400 # Optional: 24-hour token validity
5. Check for Custom Event Listeners
If you've added custom Symfony event listeners (e.g., for kernel.request), make sure they aren't forcing a redirect to the login page for the resetting path. Look for any logic that checks the request URI and redirects—you'll need to exclude paths starting with /resetting from that logic.
Start with the firewall access control rule first—it's almost always the root cause of this redirect issue. Run php bin/console cache:clear after making any config changes to ensure they take effect.
内容的提问来源于stack exchange,提问作者user4144415

