Laravel登录成功后每次请求均跳转至登录页问题求助
Hey there, I’ve run into this exact frustrating issue before—logging in successfully, only to get kicked back to the login page every time you click another admin link. Let’s break down the most likely fixes for your scenario:
1. Add the web Middleware to Your Route Group
This is the #1 culprit for this problem in Laravel 5.2+. Your current route group only uses the auth middleware, but the web middleware group includes critical components like session handling, cookie encryption, and CSRF protection that Laravel needs to track authenticated users across requests.
Update your route group to include both middleware:
Route::group(['middleware' => ['web', 'auth']], function() { Route::get('admin', function() { return view('master'); }); Route::get('admin/categories','CategoryController@index')->name('categories.index'); Route::get('admin/categories/create','CategoryController@create')->name('categories.create'); Route::post('admin/categories/store','CategoryController@store')->name('categories.store'); Route::get('admin/categories/edit/{id}','CategoryController@edit')->name('categories.edit'); Route::post('admin/categories/update/{id}','CategoryController@update')->name('categories.update'); Route::delete('admin/categories/delete/{id}','CategoryController@destroy')->name('categories.destroy'); });
2. Verify Session Configuration & Permissions
Laravel relies on sessions to persist your login state. Double-check these details:
- In your
.envfile, confirmSESSION_DRIVERis set to a valid option (likefile,database, orredis). If usingfile, make sure thestorage/framework/sessionsdirectory has read/write permissions for your server (runchmod -R 755 storageif needed). - Ensure
SESSION_DOMAINis correctly configured if you’re working with subdomains or custom domains— a mismatched domain can prevent session cookies from being saved.
3. Check Kernel Middleware Registration
Open app/Http/Kernel.php and confirm the web middleware group includes these essential entries (they should be there by default, but it’s worth verifying):
protected $middlewareGroups = [ 'web' => [ \App\Http\Middleware\EncryptCookies::class, \Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class, \Illuminate\Session\Middleware\StartSession::class, \Illuminate\View\Middleware\ShareErrorsFromSession::class, \App\Http\Middleware\VerifyCsrfToken::class, \Illuminate\Routing\Middleware\SubstituteBindings::class, ], // ... ];
The StartSession middleware is mandatory for maintaining login state across requests.
4. Clear Stale Caches
Cached routes or configs can cause unexpected behavior. Run these commands in your terminal to reset everything:
php artisan route:clear php artisan config:clear php artisan cache:clear
5. Validate CSRF Token Setup
While your issue is with GET requests, ensuring your master view includes the CSRF meta tag can prevent related session issues for POST/PUT/DELETE requests later on. Add this to the <head> section of your master.blade.php:
<meta name="csrf-token" content="{{ csrf_token() }}">
Try these steps one by one—chances are the first fix (adding the web middleware) will resolve the problem immediately. Let me know if you still hit snags!
内容的提问来源于stack exchange,提问作者mohammed talal

