Laravel应用中Ezpay报“csrf token not allowed in header”错误求助
Hey there, let's break down why your tokenization step is throwing that error and how to fix it.
What's the Root Issue?
The $.ajaxSetup you added in your layout adds Laravel's CSRF header to all jQuery AJAX requests—but EZPAY's tokenizeForm is making a cross-domain request to their payment gateway, not your backend. Here's why that's a problem:
- The EZPAY gateway doesn't care about your Laravel CSRF token—this token is only for validating requests to your own server.
- Adding a custom
X-CSRF-TOKENheader triggers a browser CORS preflight request. If EZPAY's server isn't configured to allow this custom header from your domain, the browser blocks the request entirely, which is the error you're seeing. - On top of that, EZPAY's
tokenizeFormmight not even use jQuery AJAX under the hood, so your$.ajaxSetuprule doesn't apply here anyway—it's just causing unintended side effects.
How to Fix It
1. Restrict CSRF Header to Your Own Backend Requests
Instead of applying the CSRF header globally, only add it when the request is going to your server. Modify your script like this:
<script> $.ajaxSetup({ beforeSend: function(xhr, settings) { // Only add the CSRF header for requests to your domain // Replace 'your-app-domain.com' with your actual backend domain, or use relative path check if (settings.url.startsWith('/') || settings.url.includes('your-app-domain.com')) { xhr.setRequestHeader('X-CSRF-TOKEN', '{{ csrf_token() }}'); } } }); </script>
This way, the CSRF header only gets sent to your checkout steps (which need it) and not to EZPAY's gateway.
2. Double-Check EZPAY's Tokenization Requirements
Head back to EZPAY's docs—their tokenize endpoint probably expects their own credentials (like your merchant ID, API key, etc.) instead of your Laravel CSRF token. Make sure you're passing all the parameters they require, and that you're following their recommended integration steps (like any hidden form fields or initialization configs).
3. Avoid Unnecessary Custom Headers for Cross-Domain Requests
If you were trying to pass some custom data to EZPAY, confirm if they support that via request parameters instead of headers. Cross-domain requests with custom headers are finicky because of CORS rules, so stick to the parameters EZPAY explicitly lists in their docs.
4. Consider Adding CSRF Tokens Per-Request Instead of Globally
If the global ajaxSetup feels too risky, you can just add the CSRF token directly to your own checkout step POST requests instead:
// Example for your own checkout step AJAX call $.post('/checkout/step-1', { _token: '{{ csrf_token() }}', // Your checkout data here }).done(function(response) { // Handle success });
This keeps things explicit and avoids messing with third-party scripts.
Wrap-Up
The main issue was that your global CSRF header was interfering with the cross-domain request to EZPAY's gateway. By limiting the CSRF header to only your own backend requests and following EZPAY's official integration guide, you should get the tokenization step working smoothly.
内容的提问来源于stack exchange,提问作者Geethu

