Guide
Diagnosing Contao Backend Login Redirect Loops After an Update
Step‑by‑step guide to diagnose and fix Contao backend login redirect loops after an update, covering cookie, cache, timezone, proxy, and template causes.
Published by Tasadduq Burney
15 Jul 2026, 22:51 UTC
3 min31.5K views0

Recognizable condition
After entering valid credentials in the Contao backend, the page redirects you back to the login screen without showing an error message. The browser address bar often contains a query string such as ?redirect=/contao/login.
Cause and diagnostic table
| Possible cause | What to look for |
|---|---|
| Corrupted or stale session cookies | Old session cookie persists after login attempt |
| Misconfigured cookie domain/path or HttpOnly flag | Cookie settings in system/config/localconfig.php do not match the site URL |
| Outdated cache files | Content of var/cache/prod/ dates from before the update |
| Timezone mismatch between Contao and PHP | Contao logs show timezone warnings |
| Reverse‑proxy HTTPS handling | Site is behind a load balancer that terminates SSL but Contao sees HTTP requests |
| Custom login template overriding CSRF token handling | File templates/default/login.html5 (or similar) has been modified |
Ordered checks
- Clear browser cookies for the Contao domain (e.g., via browser settings → privacy → cookies). This removes any stale session identifier.
- Delete the production cache:
rm -rf /path/to/contao/var/cache/prod/*
Run this command on the server with file‑system write permissions for the web user. - Verify timezone alignment: Ensure
date.timezoneinphp.inimatches the value set in Contao’ssystem/config/localconfig.phpunder$GLOBALS['TL_CONFIG']['defaultTimezone']. - Inspect cookie settings in
system/config/localconfig.php:$GLOBALS['TL_CONFIG']['cookieDomain']should either be empty (letting PHP use the host) or exactly match the domain without a leading dot (e.g.,www.example.com).$GLOBALS['TL_CONFIG']['cookiePath']is usually/.$GLOBALS['TL_CONFIG']['useHttpOnly']should betrueunless you have a specific reason to disable it.
- Check for proxy‑induced HTTPS loops: If the site sits behind a reverse proxy that handles SSL, add the following to
system/config/localconfig.php(or create a customsystem/config/env.php):
This tells Contao to trust the$_SERVER['HTTP_X_FORWARDED_PROTO'] = 'https'; $GLOBALS['TL_CONFIG']['forceHTTPS'] = true;X-Forwarded-Protoheader. - Revert custom login template overrides: Rename or remove any overridden
login.html5file intemplates/(or the specific theme folder) to force Contao to use the default template, which includes the CSRF token field.
Fixes tied to findings
- If clearing cookies stops the loop, the problem was a stale session cookie.
- If deleting
var/cache/prod/resolves the issue, the cache contained outdated compiled templates or service definitions. - Correcting
cookieDomainorcookiePatheliminates mismatched cookie scope. - Adding the proxy trust headers stops Contao from redirecting to HTTP when the original request was HTTPS.
- Restoring the default login template restores the CSRF token input, preventing token‑validation failures.
Escalation criteria
If the login loop persists after performing all checks above:
- Enable Contao’s debug mode by setting
$GLOBALS['TL_CONFIG']['debugMode'] = true;insystem/config/localconfig.php. - Attempt a login again and examine the log file
var/logs/prod.logfor exceptions related to session, authentication, or CSRF. - Share the relevant log excerpts with the Contao community (forum or GitHub) or consider re‑running the Contao Install Tool’s database update (
contao/install.php) to ensure schema consistency.
Verification
- After applying a fix, log in to the backend and confirm that the dashboard loads without redirection.
- Open browser developer tools → Application → Cookies and verify that the session cookie has the expected
DomainandPathvalues and is markedHttpOnly. - Check
var/logs/prod.logfor the absence of authentication‑related error messages after a successful login.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.