A 419 PAGE EXPIRED error was encountered in Laravel, usually because CSRF verification failed when the form is submitted. 1. Ensure that the @csrf directive is used correctly in the POST form; 2. AJAX requests need to manually carry CSRF tokens, which can be extracted through meta tags or attached before request; 3. Check whether the session expires or is not started, and adjust SESSION_LIFETIME appropriately; 4. Confirm whether the route is included in the web middleware group to enable CSRF protection; 5. Check the post_max_size and upload_max_filesize configurations of PHP when uploading large files to avoid interruptions.
A 419 PAGE EXPIRED error was encountered in Laravel, usually because CSRF verification failed when the form is submitted. Laravel enables CSRF protection mechanism by default. If the request does not carry a valid token, it will return a 419 page expiration error.

Here are some common solutions and precautions:
? Make sure to use the @csrf
directive correctly
If you write a POST form in the Blade template but don't add @csrf
, the request cannot be verified.

<form method="POST" action="/submit"> @csrf <!-- Other input items--> </form>
This is the most basic and easiest point to ignore. GET requests do not require CSRF tokens, but all POST, PUT, PATCH, and DELETE requests are required.
? Check whether the AJAX request carries a CSRF Token
If it is an Ajax request sent in JavaScript (such as Axios or Fetch), you need to manually bring the CSRF token.

- Method 1: Extract the token from the meta tag from the page:
<meta name="csrf-token" content="{{ csrf_token() }}">
Then set the default headers in JS:
axios.defaults.headers.common['X-CSRF-TOKEN'] = document.querySelector('meta[name="csrf-token"]').getAttribute('content');
- Method 2: Manually obtain the token before sending the request and attach it to the header or data body.
Note: Laravel will check whether the request header has
X-CSRF-TOKEN
or whether there is an_token
field passed in.
? Session expired or not started
419 The error may also be due to the loss or failure of the session, which causes the token to be verified. Common reasons include:
- The user has not operated for a long time, and the session timed out.
- The form has been opened for too long before it is submitted, and the token has expired.
- The frequent switching of multiple tabs results in inconsistent tokens.
You can adjust the expiration time of the session appropriately and modify it in the .env
file:
SESSION_LIFETIME=120
You can also consider adding a countdown to remind users to submit in time to avoid token failure.
?? Custom middleware or routing issues
Sometimes you may write middleware yourself, or put some routes outside web
middleware group, so that CSRF protection will not be automatically applied.
- Laravel's CSRF protection is implemented through
VerifyCsrfToken
middleware and is bound toweb
middleware groups by default. - If your route is not wrapped in
Route::middleware('web')
, CSRF verification will not be triggered and errors may occur.
Check the difference between routes/web.php
and routes/api.php
:
- web.php uses
web
middleware groups, including session, CSRF and other functions; - api.php uses
api
middleware group without session and CSRF.
?Special situation: The upload file is too large and the request is interrupted
Although it is not very common, if you experience a 419 error when uploading a large file, it may be that the request is interrupted by the server (for example, the PHP post_max_size
or upload_max_filesize
settings are too small), and the request does not reach Laravel at all, and the browser will jump directly to a blank page or an error page.
Check PHP configuration:
post_max_size = 32M upload_max_filesize = 32M
And restart the service to take effect.
Basically, these common reasons and ways to deal with them. Sometimes it's not the code that is wrong, but the configuration or environment problem. The recommended order of troubleshooting is: first check whether the form has @csrf
, then check whether the JS request has token, and finally check the session and server configuration.
The above is the detailed content of How to fix the 419 PAGE EXPIRED error in Laravel?. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undress AI Tool
Undress images for free

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

ToworkeffectivelywithpivottablesinLaravel,firstaccesspivotdatausingwithPivot()orwithTimestamps(),thenupdateentrieswithupdateExistingPivot(),managerelationshipsviadetach()andsync(),andusecustompivotmodelswhenneeded.1.UsewithPivot()toincludespecificcol

Laravelprovidesacleanandflexiblewaytosendnotificationsviamultiplechannelslikeemail,SMS,in-appalerts,andpushnotifications.Youdefinenotificationchannelsinthevia()methodofanotificationclass,andimplementspecificmethodsliketoMail(),toDatabase(),ortoVonage

Dependency injection automatically handles class dependencies through service containers in Laravel without manual new objects. Its core is constructor injection and method injection, such as automatically passing in the Request instance in the controller. Laravel parses dependencies through type prompts and recursively creates the required objects. The binding interface and implementation can be used by the service provider to use the bind method, or singleton to bind a singleton. When using it, you need to ensure type prompts, avoid constructor complications, use context bindings with caution, and understand automatic parsing rules. Mastering these can improve code flexibility and maintenance.

Laravel performance optimization can improve application efficiency through four core directions. 1. Use the cache mechanism to reduce duplicate queries, store infrequently changing data through Cache::remember() and other methods to reduce database access frequency; 2. Optimize database from the model to query statements, avoid N 1 queries, specifying field queries, adding indexes, paging processing and reading and writing separation, and reduce bottlenecks; 3. Use time-consuming operations such as email sending and file exporting to queue asynchronous processing, use Supervisor to manage workers and set up retry mechanisms; 4. Use middleware and service providers reasonably to avoid complex logic and unnecessary initialization code, and delay loading of services to improve startup efficiency.

Methods to manage database state in Laravel tests include using RefreshDatabase, selective seeding of data, careful use of transactions, and manual cleaning if necessary. 1. Use RefreshDatabasetrait to automatically migrate the database structure to ensure that each test is based on a clean database; 2. Use specific seeds to fill the necessary data and generate dynamic data in combination with the model factory; 3. Use DatabaseTransactionstrait to roll back the test changes, but pay attention to its limitations; 4. Manually truncate the table or reseed the database when it cannot be automatically cleaned. These methods are flexibly selected according to the type of test and environment to ensure the reliability and efficiency of the test.

LaravelSanctum is suitable for simple, lightweight API certifications such as SPA or mobile applications, while Passport is suitable for scenarios where full OAuth2 functionality is required. 1. Sanctum provides token-based authentication, suitable for first-party clients; 2. Passport supports complex processes such as authorization codes and client credentials, suitable for third-party developers to access; 3. Sanctum installation and configuration are simpler and maintenance costs are low; 4. Passport functions are comprehensive but configuration is complex, suitable for platforms that require fine permission control. When selecting, you should determine whether the OAuth2 feature is required based on the project requirements.

Laravel simplifies database transaction processing with built-in support. 1. Use the DB::transaction() method to automatically commit or rollback operations to ensure data integrity; 2. Support nested transactions and implement them through savepoints, but it is usually recommended to use a single transaction wrapper to avoid complexity; 3. Provide manual control methods such as beginTransaction(), commit() and rollBack(), suitable for scenarios that require more flexible processing; 4. Best practices include keeping transactions short, only using them when necessary, testing failures, and recording rollback information. Rationally choosing transaction management methods can help improve application reliability and performance.

The core of handling HTTP requests and responses in Laravel is to master the acquisition of request data, response return and file upload. 1. When receiving request data, you can inject the Request instance through type prompts and use input() or magic methods to obtain fields, and combine validate() or form request classes for verification; 2. Return response supports strings, views, JSON, responses with status codes and headers and redirect operations; 3. When processing file uploads, you need to use the file() method and store() to store files. Before uploading, you should verify the file type and size, and the storage path can be saved to the database.
