如何修复Laravel 5.7中「419 会话已过期,请刷新重试」问题
Hey there, I’ve dealt with this exact 419 error on Laravel 5.7 running locally on XAMPP before—let’s break down the most common fixes that usually resolve this:
1. Verify CSRF Token Setup
- First, double-check your login form includes the
@csrfBlade directive right inside the<form>tag. Laravel 5.7 requires this for CSRF validation; missing it will almost certainly trigger the 419 error. - Open your
.envfile and confirmAPP_URLmatches your HTTPS domain:APP_URL=https://laravel.platform. A mismatch here can cause session cookie inconsistencies. - If you’ve set
SESSION_DOMAINin.env, make sure it’s correctly formatted (e.g.,.laravel.platformwith a leading dot for subdomain compatibility). If you don’t need it, just comment the line out temporarily to test.
2. Fix Directory Permissions (XAMPP-Specific)
Laravel needs write access to storage/ and bootstrap/cache/ to store sessions and cache. This is a common pain point on XAMPP:
- Windows: Right-click your project folder, go to Properties > Security, and grant write permissions to
IIS_IUSRSor your current user account. - macOS/Linux: Run these commands in your project root:
(On macOS, replacechmod -R 755 storage bootstrap/cache chown -R www-data:www-data storage bootstrap/cachewww-datawith_wwwif needed.)
3. Check Session Driver Configuration
- In
.env, confirmSESSION_DRIVER=file(the default for local setups). Ensure thestorage/framework/sessions/directory exists and has proper write permissions. If you switched to thedatabasedriver, make sure you ranphp artisan session:tableand migrated the table first. - While less likely for immediate login issues, check
SESSION_LIFETIME—it defaults to 120 minutes, so a too-short value shouldn’t be the culprit here, but it’s worth verifying.
4. HTTPS Session Security Settings
Since you’re using HTTPS, tweak these .env settings to ensure session cookies are handled correctly:
- Set
SESSION_SECURE_COOKIE=trueto force session cookies over HTTPS only. - Clear your browser’s cache and cookies (specifically the
laravel_sessioncookie)—old, mismatched cookies from HTTP tests can break sessions on HTTPS.
5. Complete Cache & Configuration Reset
You already deleted bootstrap/cache/config.php, but let’s run the full suite of reset commands to ensure no stale configs are lingering:
php artisan config:clear php artisan cache:clear php artisan route:clear php artisan view:clear
6. Validate Apache .htaccess Rules
Make sure your public/.htaccess file uses the default Laravel configuration. Custom HTTPS redirect rules or broken rewrite logic can cause session data to get lost during redirects. If you modified it, replace it with the default Laravel 5.7 .htaccess content:
<IfModule mod_rewrite.c> <IfModule mod_negotiation.c> Options -MultiViews -Indexes </IfModule> RewriteEngine On # Handle Authorization Header RewriteCond %{HTTP:Authorization} . RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] # Redirect Trailing Slashes If Not A Folder... RewriteCond %{REQUEST_FILENAME} !-d RewriteCond %{REQUEST_URI} (.+)/$ RewriteRule ^ %1 [L,R=301] # Handle Front Controller... RewriteCond %{REQUEST_FILENAME} !-d RewriteCond %{REQUEST_FILENAME} !-f RewriteRule ^ index.php [L] </IfModule>
If All Else Fails: Check Laravel Logs
Dig into storage/logs/laravel.log—it will have detailed error messages that can pinpoint the root cause, like CSRF validation failures, session write errors, or permission issues you might have missed.
内容的提问来源于stack exchange,提问作者Robert Young

