Laravel 6:API的PUT与DELETE方法无法调用报403错误求助
Hey there! Let's figure out why your PUT and DELETE methods are throwing a 403 Forbidden error while GET and POST work fine. This is a super common issue in Laravel, so here are the most likely fixes to try:
1. CSRF Token Validation Blocking Requests
Laravel automatically validates CSRF tokens for non-GET requests (like POST, PUT, DELETE) when routes are defined in routes/web.php. Since you're building an API, you probably want to skip this check for your API endpoints.
Fix 1: Move routes to
routes/api.php
Routes inapi.phpare automatically excluded from CSRF verification by Laravel's default middleware stack. Just cut and paste your API routes into this file, and they'll use theapimiddleware group instead ofweb.Fix 2: Exclude routes from CSRF check (if staying in
web.php)
If you need to keep the routes inweb.php, add them to the exception list inapp/Http/Middleware/VerifyCsrfToken.php:protected $except = [ 'data/*', // Matches all data routes ];
2. Method Spoofing Issues (For HTML Form Requests)
If you're using an HTML form to send PUT/DELETE requests, remember that HTML forms don't natively support these HTTP methods. Laravel requires a hidden _method field to "spoof" the request method.
Add this hidden field to your form:
<input type="hidden" name="_method" value="PUT"> <!-- Or for DELETE: --> <input type="hidden" name="_method" value="DELETE">
Or use Laravel's helper function for cleaner code:
{{ method_field('PUT') }}
Note: This only applies if you're using HTML forms. If you're testing with tools like Postman or using AJAX (Axios, Fetch), just set the request method directly to PUT/DELETE.
3. Web Server Configuration Restrictions
Sometimes Apache or Nginx blocks PUT/DELETE requests by default. Let's check your server setup:
For Apache:
Ensure your .htaccess file (in your project root) includes the standard Laravel rewrite rules—these handle passing HTTP methods correctly to the framework. Here's what the default should look like:
<IfModule mod_rewrite.c> <IfModule mod_negotiation.c> Options -MultiViews -Indexes </IfModule> RewriteEngine On # Handle Authorization Header RewriteCond %{HTTP:Authorization} . RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] # Redirect Trailing Slashes If Not A Folder... RewriteCond %{REQUEST_FILENAME} !-d RewriteCond %{REQUEST_URI} (.+)/$ RewriteRule ^ %1 [L,R=301] # Send Requests To Front Controller... RewriteCond %{REQUEST_FILENAME} !-d RewriteCond %{REQUEST_FILENAME} !-f RewriteRule ^ index.php [L] </IfModule>
If mod_rewrite isn't enabled, you'll need to enable it via your server's control panel or terminal.
For Nginx:
Make sure your server configuration passes all requests to Laravel's index.php file, which allows Laravel to handle the HTTP methods. Your location block should look like this:
location / { try_files $uri $uri/ /index.php?$query_string; }
Also, check if any security modules (like mod_security) are restricting PUT/DELETE requests—you may need to adjust their rules to allow these methods.
4. Custom Middleware Blocking Requests
Double-check if your Api\Controller has any middleware in its constructor that might be blocking PUT/DELETE requests. For example, a permission middleware that only allows GET/POST for certain users:
// Check your controller's __construct method public function __construct() { $this->middleware('auth:api')->only(['store', 'show']); // Oops—missing update/destroy! }
Make sure all necessary methods are included in the middleware's only array, or adjust the middleware to allow the required HTTP methods.
Start with the CSRF fix first—it's the most common culprit for this issue. Let me know if any of these steps solve your problem!
内容的提问来源于stack exchange,提问作者Miten Patel

