部署Laravel应用至Heroku时遇Access Forbidden错误求助
Let’s walk through fixing this 403 issue— I’ve dealt with this exact scenario a few times, so here are the most likely fixes to get your app running on Heroku:
1. Fix Your Composer Scripts (Remove the Public Chmod)
Heroku’s dyno filesystem is read-only for most directories (including public/), so running chmod -R 777 public/ will throw an error during deployment, which might prevent your app from setting up correctly. Update your composer scripts to focus on directories that actually need write access:
"scripts": { "post-install-cmd": [ "php artisan clear-compiled", "php artisan optimize", "chmod -R 775 storage bootstrap/cache" ] }
Laravel only needs write permissions for storage/ and bootstrap/cache/ to handle logs, cache, and uploads.
2. Ensure Apache Respects .htaccess Rules
Even if you have a .htaccess in public/, Heroku’s Apache might not be allowing overrides by default. Create a public/apache.conf file with these rules:
DocumentRoot /app/public <Directory /app/public> AllowOverride All Require all granted </Directory>
Then update your Procfile to reference this config:
web: vendor/bin/heroku-php-apache2 public/ -C public/apache.conf
This forces Apache to use your .htaccess and grant proper access to the public directory.
3. Verify Your .htaccess Content
Double-check that your public/.htaccess has the default Laravel rewrite rules— missing or incorrect rules often cause 403 errors:
<IfModule mod_rewrite.c> <IfModule mod_negotiation.c> Options -MultiViews -Indexes </IfModule> RewriteEngine On # Handle Authorization Header RewriteCond %{HTTP:Authorization} . RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] # Redirect Trailing Slashes If Not A Folder... RewriteCond %{REQUEST_FILENAME} !-d RewriteCond %{REQUEST_URI} (.+)/$ RewriteRule ^ %1 [L,R=301] # Send Requests To Front Controller... RewriteCond %{REQUEST_FILENAME} !-d RewriteCond %{REQUEST_FILENAME} !-f RewriteRule ^ index.php [L] </IfModule>
4. Check Heroku Environment Variables
Make sure your APP_URL is set to your Heroku app’s full URL (e.g., https://your-app-name.herokuapp.com) and APP_ENV is set to production. You can set these via the Heroku CLI:
heroku config:set APP_URL=https://your-app-name.herokuapp.com APP_ENV=production
Incorrect APP_URL can cause routing issues that manifest as 403s.
5. Dig Into Heroku Logs
Always check the logs for specific error messages— this is the fastest way to pinpoint the root cause. Run:
heroku logs --tail
Look for lines mentioning "forbidden", "permission denied", or Apache errors. For example, if you see an error about index.php not being found, that means your document root isn’t configured correctly.
Final Deployment Step
After making these changes, commit everything and redeploy:
git add . git commit -m "Fix 403 forbidden issue on Heroku" git push heroku main
That should resolve the access forbidden error and get your Laravel app up and running!
内容的提问来源于stack exchange,提问作者Mutasim Fuad

