Laravel Dusk测试遭Chrome‘连接并非私密’拦截,求解决方案
Hey there, I’ve dealt with this exact frustrating issue when setting up Laravel Dusk tests—Chrome throwing that "not private" page and breaking test flow. Let’s go through the most reliable fixes that worked for me:
1. Add Chrome Flags to Dusk’s Driver Configuration
The simplest quick fix is to tell Chrome to ignore SSL certificate errors specifically for your Dusk tests. Modify the driver() method in your tests/DuskTestCase.php file to add two critical arguments:
protected function driver() { $options = (new ChromeOptions)->addArguments([ '--disable-gpu', '--headless=new', // Use the newer headless mode for better compatibility '--ignore-certificate-errors', // Skip certificate validation checks '--allow-insecure-localhost', // Explicitly allow insecure connections to localhost '--window-size=1920,1080', ]); return RemoteWebDriver::create( 'http://localhost:9515', DesiredCapabilities::chrome()->setCapability( ChromeOptions::CAPABILITY, $options ) ); }
This tells Chrome to bypass SSL warnings entirely during your Dusk tests, so it won’t block access to your local app.
2. Generate Trusted Local SSL Certificates
For a more permanent solution (no reliance on flags), use mkcert to create locally trusted SSL certificates:
- Install
mkcert(available for macOS, Windows, and Linux via package managers or direct download) - Run
mkcert -installto set up a local root certificate authority your system trusts - Generate a certificate for your local domain (e.g.,
mkcert myapp.test) - Configure your local web server (Laravel Valet, Nginx, Apache, or
php artisan servewith SSL flags) to use the generated.pemfiles
Once your local app serves HTTPS with a trusted certificate, Chrome will stop showing the "not private" warning entirely.
3. Modify Chrome’s Launch Shortcut (For Non-Headless Testing)
If you’re running Dusk in non-headless mode to watch browser actions, add the SSL-bypass flags directly to your Chrome shortcut:
- Right-click your Chrome shortcut and select "Properties"
- In the "Target" field, append
--ignore-certificate-errors --allow-insecure-localhost(ensure a space before the first dash) - Save changes and restart Chrome
This applies the SSL bypass every time you launch Chrome via that shortcut, great for debugging Dusk tests visually.
As for why .localhost or .test suffixes didn’t work—Chrome’s behavior around these has evolved, and even with those suffixes, it still requires a trusted SSL certificate to skip the warning. The fixes above address the root cause directly.
内容的提问来源于stack exchange,提问作者mark DE Jong

