Laravel搭建博客集成Disqus评论区遇CSRF验证失败(403)问题
Hey there, let's work through this Disqus CSRF 403 error you're hitting in your Laravel blog—this is a pretty common issue, so we'll break down the fixes step by step.
First: Confirm Disqus Trusted Domains Configuration
9 times out of 10, this error happens because Disqus doesn't recognize your site's domain as trusted. Here's how to fix that:
- Log into your Disqus account, head to the Admin panel for your blog's site
- Navigate to Settings > Advanced
- In the Trusted Domains section, add every domain your blog uses:
- Production:
yourblog.com,www.yourblog.com(include all variants you use) - Local development:
localhost:8000,127.0.0.1:8000(don't forget the port number—Disqus is strict about this)
- Production:
- Save the settings and wait 2-3 minutes for changes to propagate (Disqus sometimes takes a bit to update)
Second: Check Laravel's CSRF Exclusions (If Error Comes From Laravel)
If the 403 is being returned by your Laravel server (check your browser's Network tab to confirm), that means Laravel's CSRF middleware is blocking a Disqus-related request. This usually happens if you're handling Disqus webhooks or callbacks in your app:
- Open
app/Http/Middleware/VerifyCsrfToken.php - Add your Disqus webhook route to the
$exceptarray to skip CSRF verification for it:protected $except = [ '/disqus/webhook', // Replace with your actual webhook route ]; - Important: Only exclude routes that you know are official Disqus endpoints—don't overdo this, as it can introduce security risks.
Third: Adjust Laravel's Session Cookie SameSite Setting
Laravel's default SameSite=Strict cookie setting can block session cookies from being sent in third-party iframes (like Disqus's login iframe), which breaks their verification flow:
- Open
config/session.php - Find the
same_siteoption and change it to'lax':'same_site' => 'lax', - Clear your Laravel cache and browser cookies to apply the change:
php artisan cache:clear php artisan config:clear - This is a safe adjustment—it still maintains good security while allowing cookies to be sent during user-initiated interactions with third-party iframes.
Fourth: Verify Your Disqus Embed Code
Make sure the embed code in your Laravel views is correctly passing the right parameters to Disqus:
- Grab the official embed code from Disqus's Settings > Installation page (don't modify it unless you know what you're doing)
- Ensure you're passing the correct page URL and unique identifier in the
disqus_configfunction:<div id="disqus_thread"></div> <script> var disqus_config = function () { this.page.url = '{{ url()->current() }}'; // Pass the full URL of the current blog post this.page.identifier = '{{ $post->id }}'; // Use a unique ID for each post (like the database ID) }; (function() { var d = document, s = d.createElement('script'); s.src = 'https://your-disqus-shortname.disqus.com/embed.js'; s.setAttribute('data-timestamp', +new Date()); (d.head || d.body).appendChild(s); })(); </script> - Disqus uses the page URL and identifier to verify that the request is coming from a valid page on your site, so getting these right is crucial.
内容的提问来源于stack exchange,提问作者Dércio Lichucha

