用户头像无法显示,执行php artisan storage:link仍报403 Forbidden错误
storage:link) Hey there, let's work through this 403 issue with your user avatars—this is a super common gotcha in Laravel, so I’ll walk you through the most likely fixes step by step:
1. Double-Check Your Image Path First
First off, the src in your img tag is pointing to the server’s internal storage path (storage/app/avatars/...), which isn’t publicly accessible. When you run php artisan storage:link, Laravel creates a symlink from public/storage to storage/app/public—so your avatars should live in storage/app/public/avatars/, and your img tag should use the public-facing path:
<img src="/storage/avatars/23_avatar1548246815.bmp" alt="User Avatar">
Test this by visiting your-domain.com/storage/avatars/23_avatar1548246815.bmp directly in your browser—if the path was wrong, this will help confirm it.
2. Fix File & Directory Permissions
Web servers need read access to your storage files. Run these commands from your project root to set proper permissions:
# Set directory permissions to allow read/write/execute for owner, read/execute for others chmod -R 755 storage/ # Assign ownership to your web server user (replace www-data with nginx if using Nginx) chown -R www-data:www-data storage/
Make sure you use the correct web server user—on some systems it’s nginx instead of www-data.
3. Verify Web Server Configuration
For Nginx Users
Ensure your server block includes rules to handle the storage symlink, and that symlinks are allowed:
server { # ... other configs ... location /storage { alias /full/path/to/your/project/public/storage; try_files $uri $uri/ =404; allow all; } # Allow Nginx to follow symlinks (if not already set) disable_symlinks off; }
After updating, restart Nginx with sudo systemctl restart nginx.
For Apache Users
Check your project’s root .htaccess file to make sure it doesn’t block access to /storage, and that Apache is configured to follow symlinks. Add or confirm these lines in your Apache site config:
<Directory /full/path/to/your/project/public> Options FollowSymLinks AllowOverride All Require all granted </Directory>
Restart Apache with sudo systemctl restart apache2 after changes.
4. Check SELinux Restrictions (Linux Servers)
If you’re on a Linux system with SELinux enabled, it might be blocking the web server from accessing storage files. Test this by temporarily disabling SELinux:
setenforce 0
If the avatar loads after this, set a permanent SELinux context to allow access:
chcon -R -t httpd_sys_content_t storage/
5. Recreate the Storage Symlink
Sometimes the symlink can get corrupted or point to the wrong path. Delete the old link and recreate it:
# Delete the existing symlink rm public/storage # Recreate the link php artisan storage:link
Make sure you run this command as the same user that owns your project files (or use sudo if needed, but be careful with ownership afterward).
内容的提问来源于stack exchange,提问作者Demio Usier

