Laravel 5.8迁移后登录提示页面过期 求修复与调试方案
Hey there, let's break down this common Laravel issue step by step—since you're new to the framework, we'll focus on root causes specific to your Docker/Nginx setup and proper, secure fixes instead of workarounds.
1. Fix Nginx Configuration to Directly Serve the public Directory
Your current .htaccess workaround is redirecting traffic to /public, which can create path mismatches that break session and CSRF cookie handling. The proper Laravel setup is to have Nginx point directly to the public folder.
Update your Nginx config (usually in a nginx.conf or site-specific config file) with this setup:
server { listen 80; server_name your-app-domain.com; root /var/www/html/public; # Critical: Set root to the public directory index index.php index.html index.htm; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php$ { fastcgi_pass php-container:9000; # Replace with your PHP container name/IP fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; include fastcgi_params; } }
Restart your Nginx container after updating. This eliminates the need for complex .htaccess rules and ensures all routes/assets are served correctly from the start.
2. Fix Storage/Session Permissions (Ditch the Insecure 777)
While chmod 777 -R ./storage works temporarily, it's a security risk. In Docker, set proper ownership so the web server user (usually www-data) can write to required directories:
Run these commands inside your Laravel container:
# Set ownership for storage and bootstrap/cache chown -R www-data:www-data storage bootstrap/cache # Set secure, functional permissions chmod -R 755 storage bootstrap/cache chmod -R 775 storage/framework storage/logs
This keeps your app secure while letting Laravel write session files and logs.
3. Verify Session/Cookie Settings in .env
Even with SESSION_DRIVER=file, incorrect cookie or URL settings can break session persistence. Check these values in your .env file:
APP_URL=http://your-app-domain.com # Must match your actual access URL (include http/https) SESSION_DRIVER=file SESSION_LIFETIME=120 SESSION_DOMAIN=.your-app-domain.com # Use wildcard for subdomains, or leave empty for root domain SESSION_SECURE_COOKIE=false # Set to true only if using HTTPS
After updating, clear the config cache to apply changes:
php artisan config:clear php artisan cache:clear
4. Re-enable CSRF Protection (And Fix It Properly)
Disabling VerifyCsrfToken is a bad security practice. Let's fix the CSRF issue instead:
- Ensure your login form includes the CSRF token directive:
<form method="POST" action="/login"> @csrf <!-- This line is mandatory --> <!-- Your form fields here --> </form> - Verify the token renders in your HTML (view page source to confirm a hidden
_tokeninput exists). - For basic login forms, the
@csrfdirective is all you need—AJAX requests would require additional header setup, but that's not relevant here.
5. Debugging Steps to Diagnose the Issue
With APP_DEBUG=true, use these steps to narrow down remaining problems:
- Check session files: Look in
storage/framework/sessions—a new file should appear after loading the login page. If not, storage permissions or session config is broken. - Inspect browser cookies: Open DevTools > Application > Cookies. Confirm a
laravel_sessioncookie exists. If not, sessions aren't being set correctly (likely due to Nginx path or config issues). - Check Laravel logs: Review
storage/logs/laravel.logfor errors related to sessions or CSRF. Debug logs will often spell out exactly what's failing.
Content from Stack Exchange, asked by Nicky

