Follow the request before payment
On an isolated copy with synthetic users and disabled real payment, establish whether the failing request reaches validation or the order action. Record method, route, middleware, status and session continuity, but not cookie values or tokens. The storefront loading does not show that its later state-changing request belongs to the same active session.
- Confirm the installed Laravel version; these sources describe 12.x, not the newest major release.
- Check the form's token field or configured header against the documented frontend integration.
- Compare a fresh form with one opened before a login or other session change.
Do not exempt the buying action
Laravel documents CSRF token verification for browser state-changing requests. Its separate webhook exclusion example is not justification for excluding an ordinary checkout. Restore correct session/token handling rather than accepting any request. A token mismatch is not evidence that a payment provider declined a charge.
- Do not move order creation onto an unauthenticated GET route.
- Do not share or log token/cookie contents to debug continuity.
- Do not repeatedly submit live checkout to reproduce a rejection.
A passing framework test may not exercise CSRF
The official guide says the framework disables CSRF middleware during tests. An authored acceptance case therefore includes an isolated browser or explicitly verified middleware-enabled test route. The valid synthetic request must pass the protection; a missing or mismatched token must not cause order creation. Check existing middleware behaviour before reporting coverage.
- Assert that no test causes a charge, customer email or live fulfilment call.
- Keep the failed and passing request outcomes and source revisions.
- These are proposed cases, not an executed protected checkout.
Non-fit and priced route
One ordinary, reliably reproduced token-propagation defect may fit fix-one-bug-with-regression-test, from £295 after bounded synthetic reproduction and a fixed quote. A suspected bypass, account compromise or unauthorised order creation requires the customer's security incident route; that offer excludes it. A vendor outage, payment decline or undecided authentication design also needs a different scope. The WooCommerce repair offer does not cover a custom Laravel application.
- The initial enquiry is the redacted status, version and expected request sequence, not keys, code or live sessions.
- Prices are untested proposals; access and live changes require separate written authority.
Sources and limits
- Laravel 12.x: CSRF protection; MIT-licensed documentation, version-specific not latest-version advice Checked 2026-10-11.
- The web middleware compares a request token with its session token.
- Forms can send _token; headers provide other documented token routes.
- CSRF middleware is automatically disabled during framework tests.
- Third-party webhooks differ from browser state-changing forms.
- Laravel 12.x: session lifecycle Checked 2026-10-11.
- Session regeneration and invalidation are distinct operations.
- Current ordinary-bug offer excludes security incident handling Checked 2026-10-11.