Upgrade 8.2.0 - Getting 400 Error

Hi,

We upgraded from 8.0.3 and then as soon as we hit 8.2.0, it broke. We can get to the logon page of OpenEMR but when we click to login, we get error “This page isn’t working, If the problem continues, contact the site owner. HTTP ERROR 400”.

This is the only thing we see in the log "10.0.0.2 - - [21/Aug/2026:14:50:30 +0000] “POST /interface/main/main_screen.php?auth=login&site= HTTP/1.1” 400 - “https:///interface/login/login.php?site=default” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36”.

Can you help us get this error resolved so we can finishing upgrading to 8.2.0 and then 8.3.0?

Thanks,

Samuel Eddinger

Hi @seddinger, that looks like the access log. Could you post the php error log entries after you hit the logon page again please?

This is the only logs that we are getting when trying to login. The access log got updated, but not the error log.

10.0.0.2 - - [25/Aug/2026:16:09:29 +0000] “GET /interface/login/login.php HTTP/1.1” 200 6433 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:09:30 +0000] “GET /interface/login/login.php HTTP/1.1” 200 6433 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:09:33 +0000] “GET /interface/login/login.php?site=default HTTP/1.1” 200 6433 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36”
10.0.0.2 - - [25/Aug/2026:16:10:03 +0000] “POST /interface/main/main_screen.php?auth=login&site= HTTP/1.1” 400 - “https://openemr_domain/interface/login/login.php?site=default” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36”
10.0.0.2 - - [25/Aug/2026:16:10:27 +0000] “GET /interface/login/login.php HTTP/1.1” 200 6433 “https://teams.public.onecdn.static.microsoft/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:10:28 +0000] “GET /public/themes/style_cobalt_blue.css?v=82 HTTP/1.1” 200 353526 “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:10:28 +0000] “GET /public/assets/jquery/dist/jquery.min.js?v=82 HTTP/1.1” 200 87533 “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:10:28 +0000] “GET /interface/product_registration/product_registration_service.js?v=82 HTTP/1.1” 200 2391 “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:10:28 +0000] “GET /interface/product_registration/product_registration_controller.js?v=82 HTTP/1.1” 200 3713 “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:10:28 +0000] “GET /public/assets/bootstrap/dist/js/bootstrap.bundle.min.js?v=82 HTTP/1.1” 200 83376 “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:10:28 +0000] “GET /library/dialog.js?v=82 HTTP/1.1” 200 38058 “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:10:28 +0000] “GET /library/textformat.js?v=82 HTTP/1.1” 200 8127 “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:10:28 +0000] “GET /sites/default/images/login_logo.gif HTTP/1.1” 200 10112 “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:10:28 +0000] “GET /library/js/utility.js?v=82 HTTP/1.1” 200 26706 “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:10:28 +0000] “GET /public/assets/@fortawesome/fontawesome-free/webfonts/fa-solid-900.woff2 HTTP/1.1” 200 158220 “https://openemr_domain/public/themes/style_cobalt_blue.css?v=82” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:10:28 +0000] “GET /public/images/logos/core/favicon/favicon.ico?t=1787038455 HTTP/1.1” 200 15086 “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
127.0.0.1 - - [25/Aug/2026:16:10:34 +0000] “OPTIONS * HTTP/1.0” 200 - “-” “Apache/2.4.68 (Unix) OpenSSL/3.5.7 (internal dummy connection)”
10.0.0.2 - - [25/Aug/2026:16:10:52 +0000] “POST /interface/main/main_screen.php?auth=login&site= HTTP/1.1” 400 - “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”
10.0.0.2 - - [25/Aug/2026:16:12:03 +0000] “GET /interface/login/login.php HTTP/1.1” 200 6433 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36”
10.0.0.2 - - [25/Aug/2026:16:12:20 +0000] “POST /interface/main/main_screen.php?auth=login&site= HTTP/1.1” 400 - “https://openemr_domain/interface/login/login.php” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36”

Hi Stephen,

Are you able to help us resolve our installation HTTP 400 error with the data that we have provided?

Hi @seddinger , I asked claude to take a look and shared it below, hope this helps.

Thanks for the access log — the fact that there’s nothing at all in the PHP error log tells me this request isn’t reaching PHP; it’s being rejected by the web server (or something in front of it) before OpenEMR ever runs. A couple things to check:

  1. Can you try logging in from an incognito/private browser window (or after fully clearing cookies for this domain)? A very common cause here is old 8.0.3 session cookies stacking with new 8.2.0 cookies and exceeding the server’s header size limit — that produces exactly this symptom (GET works, POST gets a bare 400).
  2. What’s the web server topology — Apache directly, or is there nginx/a load balancer/CDN in front of it? If Dockerized, can you check the web server container’s own error log (not the PHP error log) for that timestamp?
  3. If you have access to browser dev tools, reproduce the failed login attempt with the Network tab open, and let me know the size of the request headers being sent on that failing POST.

  1. Accessed the server directly in an incognito window with disable cache in dev tools and got the same error

  2. The server is in a docker container normally behind a LB and for this test, bypassed the LB to access it in the incognito window. Looking at the container’s logs and the logs inside of the container show the same thing

    10.0.0.2 - - [27/Aug/2026:20:55:48 +0000] “POST /interface/main/main_screen.php?auth=login&site= HTTP/1.1” 400 - "https://(openemr_domain)/interface/login/login.php" “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0”

  3. 968 bytes

Thanks @seddinger.

In the Docker image, PHP’s errors get written to the Apache error log, so it’s the same file, not a separate app log. What I’d like is for you to hit the login page and attempt the login again, and then post whatever new entries show up in the error log from that attempt.

Inside the container, something like:


docker exec -it <container> tail -f /var/log/apache2/error.log

Leave that running, then try the login, and paste anything that appears.

Hi Stephen,

Yes, in the last response we’ve already have tried that, here’s the pic -

@seddinger let me be more specific, I don’t think we’re looking at the same log.

I’m not asking for what’s already in the log, but for what gets written at the moment the login fails. Two terminals, or two steps:

  1. Start the log streaming and leave it running:
docker exec -it <container_name> tail -f /var/log/apache2/error.log

  1. With that still running, go to the login page and attempt the login so it fails again.
  2. Copy and paste (as text, not a screenshot) anything new that appeared in that terminal.

If literally nothing appears, that’s a useful result too, just say so. It would tell us Apache is rejecting the request before OpenEMR’s PHP code ever runs, and we’d look at the Apache config instead.

Hi Stephen,

The pic clearly shows that nothing appears in the error logs, so what’s the next step?

Appears to me you have a javascript error reaching top.restoreSession from the ProductRegistrationService. Unclear if it would cause the bad request or if is a result of the 400

Re: My bet is that this is not a PHP issue!
Also site id is missing from request.

Hi @seddinger ,
I had my trained on openemr AI traced the OpenEMR 8.2.0 login flow, and it appears we are seeing two separate problems.

The login form is submitting this request:

POST /interface/main/main_screen.php?auth=login&site=

Notice that site= is empty. main_screen.php loads globals.php before authentication. Without a site ID in either the session or request, OpenEMR throws a missing-site exception, which returns the HTTP 400. The expected request would contain:

site=default

The top.restoreSession is not a function console error is also important, but it occurs separately. Product-registration code is not normally called directly by main_screen.php. After a successful login, main_screen.php redirects to interface/main/tabs/main.php, and that page loads the product-registration JavaScript.

Your access log contains no successful redirect or request to tabs/main.php. Instead, the product-registration scripts are being loaded by login.php before the login POST. Stock OpenEMR 8.2.0 should not load those scripts on the unauthenticated login page.

This points toward a mixed or incomplete upgrade, a customized/stale login template, stale PHP OPcache, or a session problem. The empty siteID and product-registration code appearing on the login page may both be symptoms of that underlying issue.

Please view the login page source and check whether the form action contains:

main_screen.php?auth=login&site=

Also search that source for:

product_registration_service.js

If both are present, that confirms the server is generating an incorrect login page. I would then restart Apache/PHP to clear OPcache, clear the browser cookies for this OpenEMR domain, and compare these files against the official 8.2.0 package:

interface/login/login.php
interface/globals.php
templates/login/partials/html/login_details.html.twig
interface/main/tabs/main.php

I am pretty certain this is not an openemr bug as I see many upgrades to 8.2.0 from telemetry data.
I’d not fight this issue and bypass to an 8.3.0 upgrade. I tend to believe a corrupted source is issue.

I hope this helps. One last thing I’ll do is try to force the error to prove error sequence.

Hi Stephen and Jerry,

Thanks for all your help, we have OpenEMR 8.3.0 up and running.

Samuel Eddinger

1 Like