Laravel提交含%字符表单触发406 Not Acceptable错误求助
Hey there! Let's tackle this frustrating 406 error you're hitting when submitting forms that include the % character. First off, let's clear up a key point: you don't need to manually use mysql_real_escape_string in Laravel—the framework already handles input escaping safely out of the box. Let's break down the possible causes and solutions step by step.
Why This Happens
A 406 Not Acceptable error usually means the server can't return a response matching your request's Accept headers, but in this case, it's likely triggered when submitting the form because:
- Your server's security tools (like ModSecurity) are flagging the
%character as a suspicious input - There's an issue with how the form data is being encoded before submission
Step 1: Let Laravel Handle Input Safely
Laravel's request handling and database layers automatically escape inputs to prevent SQL injection. When you use Eloquent or the query builder, parameters are bound safely—no manual escaping needed. Here's how to properly handle your form submission in a controller:
use Illuminate\Http\Request; use App\Models\Rfp; // Adjust this to your actual model public function store(Request $request) { // First, validate the incoming request $validatedData = $request->validate([ 'rfp_title' => 'required|string|max:100', 'rfp_description' => 'required|string', 'organisation' => 'required|string|max:100', 'publish_date' => 'required|date', 'closing_date' => 'required|date', 'company_image' => 'required|image|max:2048', // 2MB limit 'attachment' => 'required|file|mimes:pdf,doc,docx|max:2048', 'contact_person' => 'nullable|string|max:100', ]); // Handle file uploads (example for company_image) if ($request->hasFile('company_image')) { $imagePath = $request->file('company_image')->store('rfp_images', 'public'); $validatedData['company_image'] = $imagePath; } // Handle attachment upload similarly if ($request->hasFile('attachment')) { $attachmentPath = $request->file('attachment')->store('rfp_attachments', 'public'); $validatedData['attachment'] = $attachmentPath; } // Save to database—Eloquent automatically escapes all inputs Rfp::create($validatedData); return redirect()->back()->with('success', 'RFP submitted successfully!'); }
Step 2: Check Server Security Configurations
The most common culprit here is server-side security modules like ModSecurity (used on Apache/Nginx) that block requests containing % (since it's a URL encoding character). To fix this:
- If you have access to your server's
.htaccessfile, add these lines to disable the specific rule that's flagging the%character:
<IfModule mod_security2.c> # Disable rule that blocks % characters (adjust rule ID if needed) SecRuleRemoveById 980130 </IfModule>
- If you're on Nginx, check your
nginx.confor site-specific config for any security rules that might be filtering the request, and adjust them to allow%in form data. - If you're using a shared host, reach out to your hosting provider to ask if ModSecurity is blocking the request and if they can whitelist your form submission path.
Step 3: Ensure Proper Character Encoding
Make sure your HTML template includes the UTF-8 charset meta tag in the <head> section—this ensures form data is encoded correctly before submission:
<meta charset="UTF-8">
Your form already uses enctype="multipart/form-data" which is correct for file uploads, so no changes needed there.
Why You Don't Need mysql_real_escape_string in Laravel
Laravel uses parameter binding for all database queries, which is far more secure than manual escaping. When you use Rfp::create($validatedData) or DB::table('rfps')->insert($data), Laravel automatically escapes each value to prevent SQL injection—you never need to call mysql_real_escape_string directly.
内容的提问来源于stack exchange,提问作者Bhawesh

