Laravel项目部署至共享主机(Cpanel)表单提交出现‘Page expired’错误求助
Hey there, sorry you're hitting this frustrating CSRF error on your shared host—let's break down the most common fixes that usually resolve this, since you already confirmed the CSRF token is present in your form.
1. Use Laravel's Built-in @csrf Directive Instead of Manual Token Input
First, let's make sure your CSRF token is being generated correctly. Instead of manually writing the hidden input, switch to Laravel's Blade directive—it handles edge cases like session regeneration automatically:
<form action="lienhe" method="POST" role="lienhe"> @csrf <!-- Rest of your form fields --> </form>
This is more reliable than hardcoding the token, as it pulls directly from the active session.
2. Fix Session Permissions & Driver Configuration
Shared hosts often have strict file permissions that break Laravel's default file-based session storage. Here's what to check:
- Check storage directory permissions: Ensure the
storage/framework/sessionsfolder on your host has write permissions. Most hosts require permissions set to755(owner read/write/execute, group/others read/execute). Avoid777for security. - Switch session driver if needed: If file storage isn't working, try using the
cookiedriver (good for small apps) ordatabasedriver (more robust). Update your.envfile:
Don't forget to clear config cache after changing this (see step 4).SESSION_DRIVER=cookie
3. Correct Domain & HTTPS Settings in .env
Mismatched domain or HTTPS settings can cause cookies (which store session data) to not be sent correctly:
- Set
APP_URLto your actual host URL (includehttps://if your site uses HTTPS):APP_URL=https://yourdomain.com - Set
SESSION_DOMAINto your root domain (add a leading dot if you use subdomains):SESSION_DOMAIN=.yourdomain.com - If your host uses HTTPS, enable secure cookies:
SESSION_SECURE_COOKIE=true
4. Clear Configuration & Route Cache
Shared hosts sometimes cache old config values that don't match your live environment. If you have SSH access to your host, run these commands:
php artisan config:clear php artisan cache:clear php artisan route:clear
If you don't have SSH, you can temporarily add this code to the top of public/index.php (then remove it after loading the site once):
<?php artisan('config:clear'); artisan('cache:clear'); artisan('route:clear'); function artisan($command) { $command = implode(' ', array_slice(func_get_args(), 0)); passthru('php artisan ' . $command); }
5. Verify Form Action Path
Your form's action uses a relative path "lienhe"—if your Laravel app is installed in a subdirectory on the host (e.g., public_html/laravel), this might point to the wrong URL. Use Laravel's route() helper to generate the correct path:
First, make sure your route is named in routes/web.php:
Route::post('/lienhe', [YourController::class, 'handleContact'])->name('lienhe');
Then update your form action:
<form action="{{ route('lienhe') }}" method="POST" role="lienhe"> @csrf <!-- Form fields --> </form>
This ensures the form submits to the exact correct route every time.
6. Check for Session Lifetime Issues
While less likely for immediate "page expired" errors, double-check your SESSION_LIFETIME in .env—it should be set to a reasonable value (default is 120 minutes):
SESSION_LIFETIME=120
Start with step 1 and 2 first—those are the most common culprits for shared host CSRF issues. Let me know if any of these fix it, or if you need more details on any step!
内容的提问来源于stack exchange,提问作者Tuyen Nguyen

