PHP登录页面出现ERR_TOO_MANY_REDIRECTS重定向过多问题求助
Hey there, that sudden redirect loop error on your login page is definitely a headache—especially when everything worked fine before. Let’s walk through the most likely causes and fixes based on your setup and code snippet:
Common Causes & Troubleshooting Steps
1. Misconfigured Session-Based Redirect Logic
The #1 culprit here is a loop between your login page and home.php caused by incorrect session checks:
- If your login page automatically redirects logged-in users to
home.php, buthome.phpredirects unauthenticated users back to login... and the session isn’t being saved properly, you’ll get stuck in a loop. - Fix: Make sure both pages start with
session_start();(critical for session persistence) and double-check your redirect conditions:- On
login.php(top of the file):session_start(); // Redirect already logged-in users to home if (isset($_SESSION['user_id']) && !empty($_SESSION['user_id'])) { header("Location: home.php"); exit; // Always exit after a header redirect! } - On
home.php(top of the file):session_start(); // Redirect unauthenticated users to login if (!isset($_SESSION['user_id']) || empty($_SESSION['user_id'])) { header("Location: login.php"); exit; }
- On
2. Broken Login Validation & Redirects
Your code snippet shows you’re handling $_POST['Login'], but if you’re redirecting regardless of whether the login succeeds or fails, that can cause loops:
- For example: If you run
header("Location: home.php")even when the password is wrong,home.phpwill kick the user back to login, starting the cycle again. - Fix: Split your login logic into success/failure branches:
if (isset($_POST['Login'])) { $email = $_POST['email']; $password = $_POST['pwd']; // Complete your database query (fix the truncated SELECT statement!) $select = "SELECT id, password FROM finalfli WHERE email = ?"; $stmt = $conn->prepare($select); $stmt->bind_param("s", $email); $stmt->execute(); $result = $stmt->get_result(); if ($result->num_rows === 1) { $user = $result->fetch_assoc(); // Verify password (use password_verify if you stored hashed passwords!) if (password_verify($password, $user['password'])) { // Set session variables on successful login $_SESSION['user_id'] = $user['id']; header("Location: home.php"); exit; } else { $error = "Incorrect password"; // Stay on login page and show error—don't redirect! } } else { $error = "No account found with that email"; // Stay on login page and show error—don't redirect! } }
3. Missing or Misconfigured Session Initialization
If you forgot to add session_start(); at the very top of login.php (before any HTML or output), your session variables won’t save between requests. This means home.php will never detect the logged-in state, so it keeps redirecting back to login.
- Quick Check: Add
session_start();as the first line of every PHP file that uses sessions (login, home, etc.).
4. Cookie/Session Storage Issues
Even after clearing cookies, if your session cookie settings are broken (e.g., wrong path, domain, or secure flag), the browser won’t persist the session ID:
- You can debug this by checking your browser’s dev tools (Application tab > Cookies > localhost) to see if a PHPSESSID cookie is being set.
- If not, add this before
session_start();to reset cookie parameters (adjust as needed for your setup):session_set_cookie_params([ 'lifetime' => 3600, 'path' => '/', 'domain' => 'localhost', 'secure' => false, // Set to true if using HTTPS 'httponly' => true, 'samesite' => 'Lax' ]);
5. Hidden Database Errors
Your truncated SELECT query might be failing (e.g., typos in table/column names, database connection issues) without throwing an obvious error. If the login logic never runs properly, your session won’t be set, leading to the redirect loop.
- Fix: Enable error reporting temporarily to catch hidden issues:
error_reporting(E_ALL); ini_set('display_errors', 1);
Final Tips
- Always use prepared statements (like in the example above) to avoid SQL injection—your current code looks like it might be using raw queries, which is risky.
- After making changes, clear your browser cache/cookies again and test in incognito mode to rule out cached redirects.
内容的提问来源于stack exchange,提问作者Harinder96

