Laravel 5.5如何向客户端浏览器返回POST请求响应?
Hey there, I’ve run into this exact issue before—let’s get your POST route working smoothly. The main culprit here is almost always Laravel’s CSRF protection (which doesn’t apply to GET requests, hence why your original route worked fine). Here’s how to fix it step by step:
1. Handle CSRF Validation
Laravel automatically protects all POST/PUT/DELETE routes in web.php from cross-site request forgery. To make your POST request valid, you have a few options:
Option A: Add CSRF Token to Form Submissions
If you’re sending the request from a Laravel blade form, just include the @csrf directive inside your form tag—this generates the required CSRF token input:
<form method="POST" action="/proof"> @csrf <!-- Your form fields go here --> <button type="submit">Submit</button> </form>
Option B: Exclude the Route from CSRF Checks (For APIs/Testing Tools)
If you’re testing with tools like Postman, or building an API endpoint that doesn’t need browser-based CSRF protection, you can exclude your /proof route. Edit app/Http/Middleware/VerifyCsrfToken.php and add your route to the $except array:
protected $except = [ 'proof', ];
Note: Only do this if the route is intended for non-browser clients—skip this for user-facing form routes to keep your app secure.
Option C: Include CSRF Token in AJAX/API Request Headers
For AJAX calls (like using fetch or axios), grab the CSRF token from your page’s meta tag and include it in the request headers. First, make sure your blade template has this meta tag (it’s usually included in layouts/app.blade.php by default):
<meta name="csrf-token" content="{{ csrf_token() }}">
Then use it in your JavaScript request:
// Using fetch API fetch('/proof', { method: 'POST', headers: { 'X-CSRF-TOKEN': document.querySelector('meta[name="csrf-token"]').content, 'Content-Type': 'application/json', }, // body: JSON.stringify(yourData) // uncomment if you need to send data }) // Using axios axios.post('/proof', { // your data here }, { headers: { 'X-CSRF-TOKEN': document.querySelector('meta[name="csrf-token"]').content } })
2. Double-Check Your Client’s Request Method
It sounds obvious, but make sure your client is actually sending a POST request:
- Typing
/proofinto the browser address bar sends a GET request—use a form, Postman, or JavaScript to trigger a POST. - If you’re using AJAX, verify that you didn’t accidentally set the method to
GETin your code.
3. Optional: Allow Both GET and POST (If Needed)
If you want the route to respond to both methods (use this cautiously, especially for routes that modify data), you can use Route::match or Route::any:
// Responds to both GET and POST Route::match(['get', 'post'], 'proof', function() { $request = Place::all(); return $request; }); // Responds to ALL HTTP methods (not recommended for sensitive routes!) Route::any('proof', function() { $request = Place::all(); return $request; });
Why This Happened
GET requests are meant for retrieving data, so Laravel doesn’t enforce CSRF checks on them. POST requests, however, are for actions that change application state (like submitting forms or updating data), so Laravel uses CSRF protection to block malicious requests from unauthorized sources.
内容的提问来源于stack exchange,提问作者Jonio

