You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel搭建博客集成Disqus评论区遇CSRF验证失败(403)问题

Fixing Disqus CSRF Verification Failed (403) in Laravel

Hey there, let's work through this Disqus CSRF 403 error you're hitting in your Laravel blog—this is a pretty common issue, so we'll break down the fixes step by step.

First: Confirm Disqus Trusted Domains Configuration

9 times out of 10, this error happens because Disqus doesn't recognize your site's domain as trusted. Here's how to fix that:

  • Log into your Disqus account, head to the Admin panel for your blog's site
  • Navigate to Settings > Advanced
  • In the Trusted Domains section, add every domain your blog uses:
    • Production: yourblog.com, www.yourblog.com (include all variants you use)
    • Local development: localhost:8000, 127.0.0.1:8000 (don't forget the port number—Disqus is strict about this)
  • Save the settings and wait 2-3 minutes for changes to propagate (Disqus sometimes takes a bit to update)

Second: Check Laravel's CSRF Exclusions (If Error Comes From Laravel)

If the 403 is being returned by your Laravel server (check your browser's Network tab to confirm), that means Laravel's CSRF middleware is blocking a Disqus-related request. This usually happens if you're handling Disqus webhooks or callbacks in your app:

  • Open app/Http/Middleware/VerifyCsrfToken.php
  • Add your Disqus webhook route to the $except array to skip CSRF verification for it:
    protected $except = [
        '/disqus/webhook', // Replace with your actual webhook route
    ];
    
  • Important: Only exclude routes that you know are official Disqus endpoints—don't overdo this, as it can introduce security risks.

Laravel's default SameSite=Strict cookie setting can block session cookies from being sent in third-party iframes (like Disqus's login iframe), which breaks their verification flow:

  • Open config/session.php
  • Find the same_site option and change it to 'lax':
    'same_site' => 'lax',
    
  • Clear your Laravel cache and browser cookies to apply the change:
    php artisan cache:clear
    php artisan config:clear
    
  • This is a safe adjustment—it still maintains good security while allowing cookies to be sent during user-initiated interactions with third-party iframes.

Fourth: Verify Your Disqus Embed Code

Make sure the embed code in your Laravel views is correctly passing the right parameters to Disqus:

  • Grab the official embed code from Disqus's Settings > Installation page (don't modify it unless you know what you're doing)
  • Ensure you're passing the correct page URL and unique identifier in the disqus_config function:
    <div id="disqus_thread"></div>
    <script>
        var disqus_config = function () {
            this.page.url = '{{ url()->current() }}'; // Pass the full URL of the current blog post
            this.page.identifier = '{{ $post->id }}'; // Use a unique ID for each post (like the database ID)
        };
        (function() {
            var d = document, s = d.createElement('script');
            s.src = 'https://your-disqus-shortname.disqus.com/embed.js';
            s.setAttribute('data-timestamp', +new Date());
            (d.head || d.body).appendChild(s);
        })();
    </script>
    
  • Disqus uses the page URL and identifier to verify that the request is coming from a valid page on your site, so getting these right is crucial.

内容的提问来源于stack exchange,提问作者Dércio Lichucha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:08:01