You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel 10 + Pusher跨机器私有频道广播授权403错误求助

Laravel 10 + Pusher 跨服务器私有频道授权返回403 Forbidden

我需要实现:一台后端服务器作为数据源向私有频道推送数据,另一台机器的客户端(移动应用/服务器端客户端)连接该私有频道读取数据。当前使用Laravel 10和Pusher,同机器下私有频道授权完全正常,但外部客户端跨机器连接时始终返回403 Forbidden错误,已排查3天未解决,请求协助。

环境依赖版本

{
    "php": "^8.1",
    "guzzlehttp/guzzle": "^7.2",
    "laravel/framework": "^10.10",
    "laravel/sanctum": "^3.3",
    "laravel/tinker": "^2.8",
    "pusher/pusher-php-server": "^7.2"
}

测试环境

两台独立服务器:

  • 主后端服务器(独立域名/URL)
  • 客户端服务器(独立域名/URL)

后端频道定义(routes/channels.php)

Broadcast::channel('private.xxx.{id}', function ($deviceId) {
    return true;
});

测试结果

1. Postman直接测试授权接口

向https://backend_domain/broadcasting/auth发送POST请求,携带参数socket_id=1.2、channel_name=private.xxx.2,可正常获取授权响应。

2. 同机器客户端(Echo配置)

window.Echo.private('private.xxx.2')
    .listen('.xxx', (e) => {
        console.log('Priv Message received:', e);
    })
    .subscribed(() => {
        console.log('Subscribed to channel xxx');
    })
    .error((error) => {
        console.error('Error subscribing:', error);
    });
  • 可成功订阅频道
  • 授权请求payload:socket_id=xxx、channel_name=private-private.xxx.2

3. 跨机器客户端(Echo配置)

const authorizationHeader = `Bearer ${token}`;

window.Echo = new Echo({
    broadcaster: 'pusher',
    key: '123...',
    cluster: 'eu',
    forceTLS: true,
    authEndpoint: 'https://backend_domain/broadcasting/auth', 
    auth: {
        headers: {
            Authorization: authorizationHeader 
        }
    }
});

window.Echo.private('private.xxx.2')
    .listen('.xxx', (e) => {
        console.log('Priv Message received:', e);
    })
    .subscribed(() => {
        console.log('Subscribed to channel xxx');
    })
    .error((error) => {
        console.error('Error subscribing:', error);
    });
  • 授权请求payload与同机器一致:channel_name=private-private.xxx.2
  • 始终返回403 Forbidden错误

4. Postman额外测试

  • 使用channel_name=private.xxx.1请求,正常返回授权结果
  • 使用channel_name=private-private.xxx.1请求,返回403 Forbidden
  • 新增频道配置:
    Broadcast::channel('private-private.xxx.{id}', function ($deviceId) {
        return true;
    });
    
    测试仍返回403,但channels.php脚本可正常执行(已添加输出验证)

内容的提问来源于stack exchange,提问作者OsinskiArtur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 12:34:54