You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel 5.8迁移后登录提示页面过期 求修复与调试方案

Fixing "Page Expired Due to Inactivity" Error in Laravel 5.8 (Docker + Nginx)

Hey there, let's break down this common Laravel issue step by step—since you're new to the framework, we'll focus on root causes specific to your Docker/Nginx setup and proper, secure fixes instead of workarounds.

1. Fix Nginx Configuration to Directly Serve the public Directory

Your current .htaccess workaround is redirecting traffic to /public, which can create path mismatches that break session and CSRF cookie handling. The proper Laravel setup is to have Nginx point directly to the public folder.

Update your Nginx config (usually in a nginx.conf or site-specific config file) with this setup:

server {
    listen 80;
    server_name your-app-domain.com;
    root /var/www/html/public; # Critical: Set root to the public directory

    index index.php index.html index.htm;

    location / {
        try_files $uri $uri/ /index.php?$query_string;
    }

    location ~ \.php$ {
        fastcgi_pass php-container:9000; # Replace with your PHP container name/IP
        fastcgi_index index.php;
        fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
        include fastcgi_params;
    }
}

Restart your Nginx container after updating. This eliminates the need for complex .htaccess rules and ensures all routes/assets are served correctly from the start.

2. Fix Storage/Session Permissions (Ditch the Insecure 777)

While chmod 777 -R ./storage works temporarily, it's a security risk. In Docker, set proper ownership so the web server user (usually www-data) can write to required directories:

Run these commands inside your Laravel container:

# Set ownership for storage and bootstrap/cache
chown -R www-data:www-data storage bootstrap/cache

# Set secure, functional permissions
chmod -R 755 storage bootstrap/cache
chmod -R 775 storage/framework storage/logs

This keeps your app secure while letting Laravel write session files and logs.

Even with SESSION_DRIVER=file, incorrect cookie or URL settings can break session persistence. Check these values in your .env file:

APP_URL=http://your-app-domain.com # Must match your actual access URL (include http/https)
SESSION_DRIVER=file
SESSION_LIFETIME=120
SESSION_DOMAIN=.your-app-domain.com # Use wildcard for subdomains, or leave empty for root domain
SESSION_SECURE_COOKIE=false # Set to true only if using HTTPS

After updating, clear the config cache to apply changes:

php artisan config:clear
php artisan cache:clear

4. Re-enable CSRF Protection (And Fix It Properly)

Disabling VerifyCsrfToken is a bad security practice. Let's fix the CSRF issue instead:

  • Ensure your login form includes the CSRF token directive:
    <form method="POST" action="/login">
        @csrf <!-- This line is mandatory -->
        <!-- Your form fields here -->
    </form>
    
  • Verify the token renders in your HTML (view page source to confirm a hidden _token input exists).
  • For basic login forms, the @csrf directive is all you need—AJAX requests would require additional header setup, but that's not relevant here.

5. Debugging Steps to Diagnose the Issue

With APP_DEBUG=true, use these steps to narrow down remaining problems:

  • Check session files: Look in storage/framework/sessions—a new file should appear after loading the login page. If not, storage permissions or session config is broken.
  • Inspect browser cookies: Open DevTools > Application > Cookies. Confirm a laravel_session cookie exists. If not, sessions aren't being set correctly (likely due to Nginx path or config issues).
  • Check Laravel logs: Review storage/logs/laravel.log for errors related to sessions or CSRF. Debug logs will often spell out exactly what's failing.

Content from Stack Exchange, asked by Nicky

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 07:08:31