You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel应用中Ezpay报“csrf token not allowed in header”错误求助

Fixing the EZPAY tokenizeForm Request Failure

Hey there, let's break down why your tokenization step is throwing that error and how to fix it.

What's the Root Issue?

The $.ajaxSetup you added in your layout adds Laravel's CSRF header to all jQuery AJAX requests—but EZPAY's tokenizeForm is making a cross-domain request to their payment gateway, not your backend. Here's why that's a problem:

  • The EZPAY gateway doesn't care about your Laravel CSRF token—this token is only for validating requests to your own server.
  • Adding a custom X-CSRF-TOKEN header triggers a browser CORS preflight request. If EZPAY's server isn't configured to allow this custom header from your domain, the browser blocks the request entirely, which is the error you're seeing.
  • On top of that, EZPAY's tokenizeForm might not even use jQuery AJAX under the hood, so your $.ajaxSetup rule doesn't apply here anyway—it's just causing unintended side effects.

How to Fix It

1. Restrict CSRF Header to Your Own Backend Requests

Instead of applying the CSRF header globally, only add it when the request is going to your server. Modify your script like this:

<script>
$.ajaxSetup({
    beforeSend: function(xhr, settings) {
        // Only add the CSRF header for requests to your domain
        // Replace 'your-app-domain.com' with your actual backend domain, or use relative path check
        if (settings.url.startsWith('/') || settings.url.includes('your-app-domain.com')) {
            xhr.setRequestHeader('X-CSRF-TOKEN', '{{ csrf_token() }}');
        }
    }
});
</script>

This way, the CSRF header only gets sent to your checkout steps (which need it) and not to EZPAY's gateway.

2. Double-Check EZPAY's Tokenization Requirements

Head back to EZPAY's docs—their tokenize endpoint probably expects their own credentials (like your merchant ID, API key, etc.) instead of your Laravel CSRF token. Make sure you're passing all the parameters they require, and that you're following their recommended integration steps (like any hidden form fields or initialization configs).

3. Avoid Unnecessary Custom Headers for Cross-Domain Requests

If you were trying to pass some custom data to EZPAY, confirm if they support that via request parameters instead of headers. Cross-domain requests with custom headers are finicky because of CORS rules, so stick to the parameters EZPAY explicitly lists in their docs.

4. Consider Adding CSRF Tokens Per-Request Instead of Globally

If the global ajaxSetup feels too risky, you can just add the CSRF token directly to your own checkout step POST requests instead:

// Example for your own checkout step AJAX call
$.post('/checkout/step-1', {
    _token: '{{ csrf_token() }}',
    // Your checkout data here
}).done(function(response) {
    // Handle success
});

This keeps things explicit and avoids messing with third-party scripts.

Wrap-Up

The main issue was that your global CSRF header was interfering with the cross-domain request to EZPAY's gateway. By limiting the CSRF header to only your own backend requests and following EZPAY's official integration guide, you should get the tokenization step working smoothly.

内容的提问来源于stack exchange,提问作者Geethu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 02:30:22