Laravel 5.5与WordPress会话共享问题:如何从WP获取Laravel会话?
Hey there, let's break down why your session works on some WordPress pages but vanishes on others, and walk through the fixes to get everything synced up.
Root Cause Breakdown
The core issue boils down to two key things:
- Cookie Path/Domain Misconfiguration: Laravel's default session cookie might not be set to cover all subpaths of your domain (like
/blog/category/post-slug), or the domain setting is too restrictive. - Incomplete Laravel Bootstrap in WordPress: If your code to inject Laravel only runs on the WP homepage, deeper pages won't initialize the Laravel session at all—so
auth()->user()returns null by default.
Step-by-Step Solutions
1. Fix Laravel's Session Cookie Settings
First, make sure Laravel's session cookie is accessible across your entire domain. Update config/session.php with these settings:
return [ // ... keep your existing settings, update these: 'domain' => env('SESSION_DOMAIN', 'yourwebsite.com'), // Use your actual domain; use ".website.com" if you need subdomain support 'path' => '/', // Critical: This ensures the cookie works for all paths, including /blog and its subpages 'secure' => env('SESSION_SECURE_COOKIE', true), // Set to true if you're using HTTPS (you should be!) 'same_site' => 'lax', // Balances security and usability for cross-page navigation ];
After updating, clear Laravel's config and cache to apply changes:
php artisan config:clear php artisan cache:clear
2. Bootstrap Laravel on Every WordPress Request
Your initial functions.php code might only run on the WP homepage. Let's make sure Laravel boots up for every single WordPress page load—including deep article pages.
Add this to your WordPress child theme's functions.php:
// Bootstrap Laravel in WordPress require_once __DIR__ . '/../../vendor/autoload.php'; $app = require_once __DIR__ . '/../../bootstrap/app.php'; $kernel = $app->make(Illuminate\Contracts\Http\Kernel::class); // Capture the current request to initialize Laravel's session $request = Illuminate\Http\Request::capture(); $response = $kernel->handle($request); // Now you can access Laravel's auth system globally $laravelUser = auth()->user(); // Optional: Store the user in a global WP variable for easy access anywhere in WP global $laravel_auth_user; $laravel_auth_user = $laravelUser; // Clean up Laravel's resources after WordPress finishes loading add_action('shutdown', function() use ($kernel, $request) { $kernel->terminate($request, $response); });
This code ensures Laravel's session is fully initialized before WordPress tries to access user data, no matter which WP page the user is on.
3. Verify Cookie Availability with Browser Dev Tools
To rule out cookie issues, use your browser's developer tools (Application > Cookies):
- Check if the
laravel_sessioncookie exists, has a path of/, and matches your domain. - If the cookie is missing on deep WP pages, double-check your
SESSION_DOMAINandpathsettings in Laravel.
4. Ditch cURL/Ajax Workarounds
Your cURL and Ajax attempts are unnecessary here (and error-prone, since they require manual cookie handling). The direct Laravel bootstrap method above is the most reliable way to share sessions because both apps run on the same domain and use the same cookie.
Quick Additional Checks
- Make sure Laravel and WordPress are on the exact same domain (no subdomain mismatches like
www.website.comvswebsite.com). - If using Laravel's
filesession driver, ensure thestorage/framework/sessionsdirectory has proper permissions (chmod 755 or chown to your web server user, e.g.,www-data). - Clear your browser cookies before testing each change—stale cookies can mess with your results.
内容的提问来源于stack exchange,提问作者arhakim

