如何安全地将Laravel赛事票务选择数据发送至控制器?
Hey there! Let's break down how to securely send your selected ticket counts from single.blade.php to your controller, then display that data on payment.blade.php—all following Laravel's best practices for safety and reliability.
Step 1: Build the Ticket Selection Form in single.blade.php
First, you'll need a form that collects ticket quantities using array-named inputs. This makes it easy to group all ticket data into a single array when submitting. Don't forget Laravel's required CSRF token to prevent cross-site request forgery (CSRF) attacks.
<form action="{{ route('tickets.process', ['event' => $event->id]) }}" method="POST"> @csrf <!-- Central Stand Tickets --> <div class="mb-4"> <label for="central_tickets" class="block font-medium text-gray-700">Central Stand Tickets</label> <select name="tickets[central]" id="central_tickets" class="mt-1 block w-full"> @for ($i = 0; $i <= 10; $i++) <option value="{{ $i }}">{{ $i }}</option> @endfor </select> </div> <!-- Left Stand Tickets --> <div class="mb-4"> <label for="left_tickets" class="block font-medium text-gray-700">Left Stand Tickets</label> <select name="tickets[left]" id="left_tickets" class="mt-1 block w-full"> @for ($i = 0; $i <= 10; $i++) <option value="{{ $i }}">{{ $i }}</option> @endfor </select> </div> <!-- Add more ticket types here if needed --> <button type="submit" class="bg-blue-500 hover:bg-blue-600 text-white px-4 py-2 rounded">Next to Payment</button> </form>
Step 2: Define a Route for the Form Submission
Add a POST route in routes/web.php that points to a controller method where we'll process the ticket data:
use App\Http\Controllers\TicketController; Route::post('/event/{event}/process-tickets', [TicketController::class, 'processSelection']) ->name('tickets.process');
Step 3: Process the Data in the Controller
Create (or update) TicketController.php to validate, filter, and store the ticket data. We'll use Laravel's session to persist the data so it's available on the payment page—this is safer than passing data via URL parameters.
namespace App\Http\Controllers; use Illuminate\Http\Request; class TicketController extends Controller { public function processSelection(Request $request, $eventId) { // 1. Validate the incoming data (server-side validation is non-negotiable!) $validated = $request->validate([ 'tickets' => 'required|array', 'tickets.*' => 'integer|min:0|max:10', // Adjust max based on your ticket limits ]); // 2. Filter out tickets with 0 quantity to avoid cluttering the payment page $selectedTickets = array_filter($validated['tickets'], function ($quantity) { return $quantity > 0; }); // 3. Store the filtered ticket data in the session session()->put('selected_tickets', $selectedTickets); session()->put('event_id', $eventId); // Optional: Store event ID if needed for payment // 4. Redirect to the payment page return redirect()->route('payment.show'); } }
Step 4: Display the Data on payment.blade.php
Retrieve the ticket data from the session and display it to the user. You can also add a check to handle cases where someone tries to access the payment page without selecting tickets first.
<div class="mb-6"> <h2 class="text-xl font-bold mb-4">Your Selected Tickets</h2> @if(session()->has('selected_tickets')) <ul class="space-y-2"> @foreach(session('selected_tickets') as $type => $quantity) <li class="flex justify-between items-center p-2 bg-gray-50 rounded"> <span class="capitalize">{{ $type }} stand tickets</span> <span class="font-medium">{{ $quantity }} x ${{ $ticketPrices[$type] }}</span> <!-- Replace with actual pricing logic --> </li> @endforeach </ul> @else <p class="text-red-500">No tickets selected. Please go back to the event page to choose your tickets.</p> <a href="{{ route('event.show', session('event_id')) }}" class="mt-2 inline-block text-blue-500 hover:underline">Back to Event</a> @endif </div> <!-- Add your payment form here -->
Key Safety Notes
- CSRF Protection: Always include
@csrfin your form—Laravel blocks POST requests without this token by default. - Server-Side Validation: Never rely solely on frontend validation; users can bypass it. The
validate()method ensures only valid integer quantities are accepted. - Session Storage: Using sessions keeps sensitive data (like ticket counts or event IDs) out of the URL, preventing tampering or exposure.
- Filter Empty Data: Removing tickets with 0 quantity keeps the payment page clean and avoids unnecessary processing.
内容的提问来源于stack exchange,提问作者johnW

