Reputation: 81
I'm using Symfony 5.3.1 and I'm implementing the default authentication system.
When I register a new user using the automatically created register template is perfectly working and the user is added to my MySQL database.
But, when I log in a user in the /login template nothing happens. No redirect. No error.
What I expect is onAuthenticationSuccess being called from /Security/LoginAuthenticator.
This is my /Security/LoginAuthenticator
namespace App\Security;
use Symfony\Component\HttpFoundation\RedirectResponse;
use Symfony\Component\HttpFoundation\Request;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\Routing\Generator\UrlGeneratorInterface;
use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
use Symfony\Component\Security\Core\Security;
use Symfony\Component\Security\Http\Authenticator\AbstractLoginFormAuthenticator;
use Symfony\Component\Security\Http\Authenticator\Passport\Badge\CsrfTokenBadge;
use Symfony\Component\Security\Http\Authenticator\Passport\Badge\UserBadge;
use Symfony\Component\Security\Http\Authenticator\Passport\Credentials\PasswordCredentials;
use Symfony\Component\Security\Http\Authenticator\Passport\Passport;
use Symfony\Component\Security\Http\Authenticator\Passport\PassportInterface;
use Symfony\Component\Security\Http\Util\TargetPathTrait;
class LoginAuthenticator extends AbstractLoginFormAuthenticator
use TargetPathTrait;
public const LOGIN_ROUTE = 'app_login';
private UrlGeneratorInterface $urlGenerator;
public function __construct(UrlGeneratorInterface $urlGenerator)
$this->urlGenerator = $urlGenerator;
public function authenticate(Request $request): PassportInterface
$username = $request->request->get('username', '');
$request->getSession()->set(Security::LAST_USERNAME, $username);
return new Passport(
new UserBadge($username),
new PasswordCredentials($request->request->get('password', '')),
new CsrfTokenBadge('authenticate', $request->get('_csrf_token')),
public function onAuthenticationSuccess(Request $request, TokenInterface $token, string $firewallName): ?Response
if ($targetPath = $this->getTargetPath($request->getSession(), $firewallName)) {
return new RedirectResponse($targetPath);
// For example:
//return new RedirectResponse($this->urlGenerator->generate('some_route'));
throw new \Exception('TODO: provide a valid redirect inside '.__FILE__);
protected function getLoginUrl(Request $request): string
return $this->urlGenerator->generate(self::LOGIN_ROUTE);
This is my security.yaml:
algorithm: auto
enable_authenticator_manager: true
# used to reload user from session & other features (e.g. switch_user)
class: App\Entity\User
property: username
pattern: ^/(_(profiler|wdt)|css|images|js)/
security: false
lazy: true
provider: app_user_provider
path: app_logout
# where to redirect after logout
target: link.index
custom_authenticator: App\Security\LoginAuthenticator
# activate different ways to authenticate
# switch_user: true
# Easy way to control access for large sections of your site
# Note: Only the *first* access control that matches will be used
# - { path: ^/admin, roles: ROLE_ADMIN }
# - { path: ^/profile, roles: ROLE_USER }
And finally this is my SecurityController:
namespace App\Controller;
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\Routing\Annotation\Route;
use Symfony\Component\Security\Http\Authentication\AuthenticationUtils;
class SecurityController extends AbstractController
* @Route("/login", priority=10, name="app_login")
public function login(AuthenticationUtils $authenticationUtils): Response
// if ($this->getUser()) {
// return $this->redirectToRoute('target_path');
// }
// get the login error if there is one
$error = $authenticationUtils->getLastAuthenticationError();
// last username entered by the user
$lastUsername = $authenticationUtils->getLastUsername();
return $this->render('security/login.html.twig', ['last_username' => $lastUsername, 'error' => $error]);
* @Route("/logout", priority=12, name="app_logout")
public function logout()
throw new \LogicException('This method can be blank - it will be intercepted by the logout key on your firewall.');
I have being 2 days looking for a solution and nothing worked. Here is a picture of my login form:
After clicking Sign in, the page is refreshed and nothing happens.
Thank you.
Upvotes: 0
Views: 1929
Reputation: 81
I was using a server from bitnami MAMP and I changed to:
php -S localhost:8000 -t public
This solved my problem.
Credits to the youtube channel "Art of coding" who figured out this and helped me. Credits also for the user Cerad who also helped me.
Upvotes: 1