mkastoun/laravel-419-handler

Graceful handling of Laravel 419 session expired errors.

Installs: 68

Dependents: 0

Suggesters: 0

Security: 0

Stars: 0

Watchers: 1

Forks: 0

Open Issues: 0

pkg:composer/mkastoun/laravel-419-handler

v1.1.2 2025-05-27 12:57 UTC

This package is auto-updated.

Last update: 2025-09-27 13:42:27 UTC


README

Gracefully handle 419 Page Expired errors in Laravel using a clean, package-based trait that integrates into your Handler.php.

✨ Features

  • Handles TokenMismatchException (CSRF/session expiration)
  • Clean trait-based integration (no overriding core Laravel handlers)
  • Redirects with flash messages (web)
  • JSON error response (API)
  • Configurable behavior

πŸ“¦ Installation

Via Composer:

composer require mkastoun/laravel-419-handler

βš™οΈ Publish Configuration

php artisan vendor:publish --provider="Laravel419Handler\Laravel419HandlerServiceProvider" --tag=config

Configuration (config/laravel419.php)

return [
    'redirect_on_web' => '/',
    'flash_message' => 'Your session has expired. Please try again.',
    'auto_refresh_on_back' => true,
    'json_response' => [
        'message' => 'Session expired. Please try again.',
        'status' => 419,
    ],
];

🧩 Integration

In your App\Exceptions\Handler.php:

  1. Import and use the trait:
use Laravel419Handler\Traits\HandlesTokenMismatch;
use Illuminate\Session\TokenMismatchException;

class Handler extends ExceptionHandler
{
    use HandlesTokenMismatch;

    public function render($request, Throwable $e)
    {
        if ($e instanceof TokenMismatchException) {
            return $this->handleTokenMismatch($request, $e);
        }

        return parent::render($request, $e);
    }
}
  1. In your Blade layout, show the flash error (Optional):
@if(session('error'))
    <div class="alert alert-danger">
        {{ session('error') }}
    </div>
@endif

πŸ§ͺ Testing

composer test

πŸ“„ License

MIT

🀝 Contributing

PRs welcome! Please submit issues, ideas, and improvements to help others benefit from this package.

🧠 Why Not Middleware?

While catching 419s via middleware is sometimes possible, it’s not 100% reliable because TokenMismatchException is thrown before controller or middleware logic in some cases. Using a trait inside the exception handler guarantees full coverage β€” safely and cleanly.