Laravel API+VueJS部署Nginx后POST请求/oauth/token报405错误
/oauth/token on Nginx Hey there, let's troubleshoot that 405 Method Not Allowed error you're seeing when hitting the /oauth/token endpoint on your Nginx-deployed Laravel app. Since you've already ruled out route issues, this is almost certainly an Nginx configuration problem—built-in PHP servers like artisan serve handle requests much differently than Nginx.
Here are the most likely fixes to try:
1. Ensure Nginx Allows POST (and Other) Request Methods
Nginx often restricts allowed request methods in location blocks by default. If your config only permits GET/HEAD, POST requests to /oauth/token will get rejected outright.
Update your Nginx server block to explicitly allow the necessary methods:
server { listen 80; server_name project.local; root /path/to/your/laravel/public; index index.php index.html index.htm; location / { try_files $uri $uri/ /index.php?$query_string; # Allow all required HTTP methods for your app allow_methods GET POST PUT DELETE OPTIONS; } location ~ \.php$ { fastcgi_pass unix:/var/run/php/php8.2-fpm.sock; # Adjust to your PHP-FPM socket path fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; include fastcgi_params; # Don't forget to allow POST here too—this is where PHP processes the request allow_methods GET POST PUT DELETE OPTIONS; } }
2. Handle OPTIONS Preflight Requests (If CORS Is Involved)
If your Vue frontend runs on a different port (like localhost:8080) than your Nginx server (project.local:80), browsers will send an OPTIONS preflight request before the actual POST. Nginx might block this, or Laravel might not be configured to handle it properly.
Option A: Nginx-Level OPTIONS Handling
Add this block inside your server config to respond to OPTIONS requests directly:
if ($request_method = OPTIONS) { # Replace * with your frontend domain in production (e.g., http://localhost:8080) add_header Access-Control-Allow-Origin "*"; add_header Access-Control-Allow-Methods "GET, POST, PUT, DELETE, OPTIONS"; add_header Access-Control-Allow-Headers "Authorization, Content-Type, X-Requested-With"; return 204; }
Option B: Laravel CORS Configuration
If you prefer handling CORS within Laravel, use the barryvdh/laravel-cors package:
- Install it:
composer require barryvdh/laravel-cors - Publish the config:
php artisan vendor:publish --provider="Barryvdh\Cors\ServiceProvider" - Update
config/cors.phpto include the Passport endpoint:'paths' => ['api/*', 'oauth/*', 'sanctum/csrf-cookie'], 'allowed_methods' => ['*'], // Adjust allowed_origins to match your frontend domain for production
3. Verify Nginx Rewrite Rules Are Correct
A common mistake is missing the ?$query_string in the try_files directive. Without this, POST request data might not be passed to Laravel correctly, leading to unexpected errors.
Double-check that your location / block has:
try_files $uri $uri/ /index.php?$query_string;
4. Confirm Requests Are Reaching Laravel
Check your Laravel logs (storage/logs/laravel.log) to see if the POST request to /oauth/token is being logged. If it's not, Nginx isn't forwarding the request to Laravel at all—double-check your root path and fastcgi configuration to ensure they point to your Laravel app's public directory.
5. Restart Services After Changes
Don't forget to apply your Nginx and PHP-FPM changes:
sudo systemctl restart nginx sudo systemctl restart php8.2-fpm # Adjust to your PHP version (e.g., php7.4-fpm)
These steps should resolve the 405 error—most of the time, it's either Nginx blocking POST methods or misconfigured rewrite rules preventing the request from reaching Laravel's Passport handler.
内容的提问来源于stack exchange,提问作者Sombrero

