douzhan1238 2014-11-07 22:14
浏览 99
已采纳

Symfony 2.3登录表单未进行身份验证

I'm trying to implement a rather basic login form with Symfony2.3, but I'm running into an error where I'm sometimes redirected to the expected page after providing correct credentials, but sometimes not (instead I'm just redirected back to the login page). Here is my security.yml file:

security:
    encoders:
        Symfony\Component\Security\Core\User\User: plaintext
        Acme\MyBundle\Entity\User: sha512
    providers:
        main:
            id: acme.user.provider
    firewalls:
        dev:
            pattern: ^/(_(profiler|wdt)|css|images|js)/
            security: false
        login_firewall:
            pattern: ^/login$
            security: false
        secured_area:
            pattern: ^/
            form_login: ~
            logout:
                path:   /logout
                target: /
    access_control:
        - { path: ^/login$, roles: IS_AUTHENTICATED_ANONYMOUSLY, requires_channel: https }
        - { path: ^/, roles: ROLE_USER, requires_channel: https }

Here is my SecurityController:

<?php

namespace Acme\MyBundle\Controller;

use Sensio\Bundle\FrameworkExtraBundle\Configuration\Route;
use Sensio\Bundle\FrameworkExtraBundle\Configuration\Template;
use Symfony\Component\HttpFoundation\Request;
use Symfony\Component\Security\Core\SecurityContextInterface;

/**
 * Class SecurityController
 * @package Acme\MyBundle\Controller
 *
 * @Route("/")
 */
class SecurityController extends Controller
{
    /**
     * @param Request $request
     * @return \Symfony\Component\HttpFoundation\Response
     *
     * @Route("/login", requirements={"_scheme" = "https"}, path="login")
     */
    public function LoginAction(Request $request)
    {
        $session = $request->getSession();

        // get the login error if there is one
        if ($request->attributes->has(SecurityContextInterface::AUTHENTICATION_ERROR)) {
            $error = $request->attributes->get(
                SecurityContextInterface::AUTHENTICATION_ERROR
            );
        } elseif (null !== $session && $session->has(SecurityContextInterface::AUTHENTICATION_ERROR)) {
            $error = $session->get(SecurityContextInterface::AUTHENTICATION_ERROR);
            $session->remove(SecurityContextInterface::AUTHENTICATION_ERROR);
        } else {
            $error = '';
        }

        // last username entered by the user
        $lastUsername = (null === $session) ? '' : $session->get(SecurityContextInterface::LAST_USERNAME);

        return $this->render(
            'AcmeMyBundle:Security:login.html.twig',
            array(
                // last username entered by the user
                'last_username' => $lastUsername,
                'error'         => $error,
            )
        );
    }

    /**
     * @Route("/login_check", requirements={"_scheme" = "https"}, path="login_check")
     */
    public function LoginCheckAction()
    {

    }

    /**
     * @Route("/logout", requirements={"_scheme" = "https"}, path="logout")
     */
    public function LogoutAction()
    {

    }
}

And here is my bundle's routing.yml file:

_security:
    resource: "@AcmeMyBundle/Controller/SecurityController.php"
    type: annotation

When I provide the proper credentials, I'm correctly logged in / redirected to the given URL about 20% of the time. The other 80% of the time I'm just redirected back to the form login page with no error message. I also don't see any error message when I try to login with incorrect credentials.

UPDATE: It looks like the issue is that Symfony is creating more than one session in my database on each request. I am using the pdo handler.

  • 写回答

2条回答 默认 最新

  • dongxun7962 2014-11-10 14:44
    关注

    Turns out the issue was actually with the Session entity / table in which I was storing my session. I was using the PDOSessionHandler to store sessions in the database, and had the following $id in my ORM Session entity:

    <?php
    
    namespace Acme\MyBundle\Entity;
    
    use Doctrine\ORM\Mapping as ORM;
    
    /**
     * Session
     *
     * @ORM\Table()
     * @ORM\Entity
     */
    class Session
    {
        /**
         * @var integer
         *
         * @ORM\Column(name="id", type="integer")
         * @ORM\Id
         * @ORM\GeneratedValue(strategy="AUTO")
         */
        private $id;
    

    The $id should not have been of type integer, but (obviously (-_-) of type string. After changing the property to:

    /**
     * @var integer
     *
     * @ORM\Column(type="string", length=255)
     * @ORM\Id
     */
    private $id;
    

    and running php app/console doctrine:schema:update --force, everything appears to be working correctly.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?

悬赏问题

  • ¥20 ue5运行的通道视频都会有白色锯齿
  • ¥20 用雷电模拟器安装百达屋apk一直闪退
  • ¥15 算能科技20240506咨询(拒绝大模型回答)
  • ¥15 自适应 AR 模型 参数估计Matlab程序
  • ¥100 角动量包络面如何用MATLAB绘制
  • ¥15 merge函数占用内存过大
  • ¥15 Revit2020下载问题
  • ¥15 使用EMD去噪处理RML2016数据集时候的原理
  • ¥15 神经网络预测均方误差很小 但是图像上看着差别太大
  • ¥15 单片机无法进入HAL_TIM_PWM_PulseFinishedCallback回调函数