#42866·PrestaShop

Recursive back URL parameter

Author: lmeyer1Created Sep 17, 2026Updated Sep 17, 2026

Prerequisites

Describe the bug and add attachments

Discovering:

We get infinite recursion URL in webserver log, like GET /fr/connexion?back=https://example.com/fr/connexion?back=https%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Fde%2Fanmeldung%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fconnexion%3Fback%3Dhttps%3A%2F%2Fexample.com%2Ffr%2Fauthor%2F14303-white-paula%3Fpage%3D6

Root cause:

classes/controller/FrontController.php:1549

'current_url' => $this->context->shop->getBaseURL(true, false) . $_SERVER['REQUEST_URI'],

This builds the current_url template variable by blindly concatenating the raw request URI — including any query string the current page already has, back=... included. It's consumed by modules/ps_customersignin/ps_customersignin.tpl:30:

href="{$urls.pages.authentication}?back={$urls.current_url}"

That "Sign in" link is in the header, rendered on every page a visitor isn't logged in on — including the login page itself. So on /connexion?back=X, the page's own current_url is .../connexion?back=X, and the "Sign in" link on that page points to /connexion?back=.../connexion?back=X — one layer deeper, single-urlencoded. A crawler treats each hop as a distinct URL and keeps following it, growing the URL by one more anmeldung?back= wrapper every time. That's a classic self-inflicted crawler trap, it's pure recursive link generation.

Fix:

Strip any pre-existing back parameter when building current_url, so the chain can't nest. This also happens to be correct for the other two consumers of current_url (og:url and JSON-LD url in microdata-jsonld.tpl) — a canonical/OG URL shouldn't carry a transient redirect param anyway.

Steps to reproduce

If you are using ps_customersignin, you will probable find this pattern in the Apache access log.

To reproduce without looking at the server log:

  1. Go to the logline page with ps_customersignin module activated
  2. Click on the Log in to your customer account link
  3. Each click, the URL gets longer with an additional recursive back parameter

Expected behavior

back parameters should never be recursive.

Actual Result

No response

PrestaShop version where the bug happens

8.1.3

How have you installed PrestaShop

I'm using git clone on a modified private github repo

PHP version(s) where the bug happened

8.1

Your company or customer's name goes here (if applicable).

No response