You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

用户头像无法显示,执行php artisan storage:link仍报403 Forbidden错误

Hey there, let's work through this 403 issue with your user avatars—this is a super common gotcha in Laravel, so I’ll walk you through the most likely fixes step by step:

1. Double-Check Your Image Path First

First off, the src in your img tag is pointing to the server’s internal storage path (storage/app/avatars/...), which isn’t publicly accessible. When you run php artisan storage:link, Laravel creates a symlink from public/storage to storage/app/public—so your avatars should live in storage/app/public/avatars/, and your img tag should use the public-facing path:

<img src="/storage/avatars/23_avatar1548246815.bmp" alt="User Avatar">

Test this by visiting your-domain.com/storage/avatars/23_avatar1548246815.bmp directly in your browser—if the path was wrong, this will help confirm it.

2. Fix File & Directory Permissions

Web servers need read access to your storage files. Run these commands from your project root to set proper permissions:

# Set directory permissions to allow read/write/execute for owner, read/execute for others
chmod -R 755 storage/
# Assign ownership to your web server user (replace www-data with nginx if using Nginx)
chown -R www-data:www-data storage/

Make sure you use the correct web server user—on some systems it’s nginx instead of www-data.

3. Verify Web Server Configuration

For Nginx Users

Ensure your server block includes rules to handle the storage symlink, and that symlinks are allowed:

server {
    # ... other configs ...

    location /storage {
        alias /full/path/to/your/project/public/storage;
        try_files $uri $uri/ =404;
        allow all;
    }

    # Allow Nginx to follow symlinks (if not already set)
    disable_symlinks off;
}

After updating, restart Nginx with sudo systemctl restart nginx.

For Apache Users

Check your project’s root .htaccess file to make sure it doesn’t block access to /storage, and that Apache is configured to follow symlinks. Add or confirm these lines in your Apache site config:

<Directory /full/path/to/your/project/public>
    Options FollowSymLinks
    AllowOverride All
    Require all granted
</Directory>

Restart Apache with sudo systemctl restart apache2 after changes.

4. Check SELinux Restrictions (Linux Servers)

If you’re on a Linux system with SELinux enabled, it might be blocking the web server from accessing storage files. Test this by temporarily disabling SELinux:

setenforce 0

If the avatar loads after this, set a permanent SELinux context to allow access:

chcon -R -t httpd_sys_content_t storage/

Sometimes the symlink can get corrupted or point to the wrong path. Delete the old link and recreate it:

# Delete the existing symlink
rm public/storage
# Recreate the link
php artisan storage:link

Make sure you run this command as the same user that owns your project files (or use sudo if needed, but be careful with ownership afterward).


内容的提问来源于stack exchange,提问作者Demio Usier

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 08:47:27