Laravel 5-AJAX图像上传与CSRF保护


Laravel 5 - AJAX image upload with CSRF protection

我设置了一个表单来上传图像。我以前使用过DropZone.js,它运行良好,并在ajax调用的同时发送了CSRF令牌。服务器端的一切都很好,但当尝试在没有DropZone的情况下这样做时,我会遇到令牌不匹配的错误。

这是我的AJAX调用:

    $(document).on('submit', ".hidden-image-upload", function(e){
    e.preventDefault();
    $.ajax({
        url:'/project/uploadImage',
        data:{
            data:new FormData($("#upload_form")[0]),
        },
        dataType:'json',
        async:false,
        type:'post',
        processData: false,
        contentType: false,
        success:function(response){
            console.log(response);
        },
    });
});

这就是HTML:

<form method="POST" action="http://localhost/project/create" accept-charset="UTF-8" class="hidden-image-upload">
    <input name="_token" type="hidden" value="5lgtt8AgbeF3lprptj8HNXVPceRhoJbqBeErBI1k">
    <input class="cover-image-upload-button" name="file" type="file">
</form>

我该如何整理我的AJAX调用/Laravel以协同工作?

您可以使用$.ajax.在标头中发送令牌

$(document).on('submit', ".hidden-image-upload", function(e){
    e.preventDefault();
    $.ajax({
        url:'/project/uploadImage',
        data:{
            data:new FormData($("#upload_form")[0]),
        },
        headers: {
           'X-CSRF-Token': $('form.hidden-image-upload [name="_token"]').val()
        }
        dataType:'json',
        async:false,
        type:'post',
        processData: false,
        contentType: false,
        success:function(response){
            console.log(response);
        },
    });
});

在最坏的情况下,在该路由中禁用CSRF检查,只需在数组$中添加路由,但在app/Http/Middleware/VerifyCsrfToken.php

中除外

试试这个。您还必须将您的CSRF代币与FormData:一起传递

$(document).on('submit', ".hidden-image-upload", function(e){
e.preventDefault();
var data = new FormData($("#upload_form")[0]);
    data.append('_token', $('input[name="token"]').val());
$.ajax({
    url:'/project/uploadImage',
    data:{
        data: data,
    },
    dataType:'json',
    async:false,
    type:'post',
    processData: false,
    contentType: false,
    success:function(response){
        console.log(response);
    },
});

});