Laravel服务器出现ERR_TOO_MANY_REDIRECTS错误求助
Hey there! Let’s break down this redirect loop issue you’re hitting—local works fine, but the server throws that cookie-related redirect error. Let’s look at both code and server config angles, since either could be the culprit.
First, Let’s Analyze Your Route Code
Your routes look mostly standard: you’re using Route::auth() to get Laravel’s default auth routes, then wrapping protected routes (including the root /) in the auth middleware. On its own, this shouldn’t cause a loop—normally, unauthenticated users hitting / get redirected to /login, which is unprotected. But here’s what to check in code:
- Session Configuration Mismatch: The most common cookie-related redirect loop comes from session settings not matching your server environment.
- Open
config/session.phpand check thesecureoption. If your server uses HTTPS (which it should!), this should be set totrueornull(Laravel auto-detects HTTPS). If it’s set tofalseon an HTTPS server, browsers might block the session cookie as insecure, meaning Laravel never sees the login session and keeps redirecting you to login. - Also check the
domainoption insession.php. If your server’s domain is different from your local environment (e.g.,your-app.comvslocalhost), make sure this is set correctly—otherwise the cookie won’t be attached to requests, leading to endless redirects.
- Open
- Middleware Customizations: Did you modify the default
Authmiddleware or add any custom redirect logic? For example, if you changed theredirectTomethod inapp/Http/Middleware/Authenticate.phpto point to a route that’s also protected byauth, that would create a loop. - Route Conflicts: Double-check if there’s another route definition for
/outside theauthmiddleware group. If so, Laravel might be matching that route first, but then some other logic redirects you back—though if this worked locally, this is less likely.
Next, Check Server Configuration
Since it works locally but breaks on the server, environment-specific config is often the issue:
- HTTPS Header Forwarding: If your server uses a reverse proxy (like Nginx with a load balancer, or services like Heroku/Cloudflare), Laravel might not detect that the request is over HTTPS. This makes the
securesession cookie not get set, because Laravel thinks it’s on HTTP.- For Nginx, make sure your config includes these headers to pass HTTPS info to Laravel:
proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-For $remote_addr; - Then update
app/Http/Middleware/TrustProxies.phpto trust your proxy’s IP address (or set'*'temporarily for testing, but don’t leave it that way in production).
- For Nginx, make sure your config includes these headers to pass HTTPS info to Laravel:
- Server-Level Redirects: If your server has a rule to force HTTPS (e.g., Nginx redirecting HTTP to HTTPS), make sure it’s configured correctly. A miswritten rule could create a loop with Laravel’s auth redirects. For example, if the rule redirects all requests to HTTPS but doesn’t exclude the login route (though that’s unlikely, but worth checking).
- Cookie Path/Domain Restrictions: Some servers have strict cookie policies. Check if your server is setting any additional cookie headers that conflict with Laravel’s. For example, if the server sets a
Path=/admincookie but your app uses/, that could prevent the session cookie from being read.
Step-by-Step Debugging Actions
- Test the Login Route Directly: Visit
your-server-domain/logindirectly. If it loads, try logging in. If you get redirected back to login immediately, that confirms the session cookie isn’t being saved—focus on session config and HTTPS headers. - Clear Server Cache: Run these commands on your server to clear cached config/routes, which might be holding onto local settings:
php artisan config:cache php artisan route:cache php artisan cache:clear - Inspect Cookies in Dev Tools: Use your browser’s developer tools (Application tab in Chrome/Firefox) to check if a
laravel_sessioncookie is being set after login. If not, check the console for cookie-related errors (like "Secure cookie set on insecure request").
Wrap-Up
This is almost always a cookie/session issue caused by environment mismatches between local and server. The most likely fixes are adjusting your session.php config for HTTPS/domain, or fixing your server’s HTTPS header forwarding. Code issues are possible but less probable since it works locally.
内容的提问来源于stack exchange,提问作者Benjamin Gonzales

