惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
T
Tailwind CSS Blog
Recent Announcements
Recent Announcements
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
P
Proofpoint News Feed
D
Docker
Google DeepMind News
Google DeepMind News
aimingoo的专栏
aimingoo的专栏
B
Blog RSS Feed
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
云风的 BLOG
云风的 BLOG
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
WordPress大学
WordPress大学
IT之家
IT之家
H
Help Net Security
Apple Machine Learning Research
Apple Machine Learning Research
Martin Fowler
Martin Fowler
S
SegmentFault 最新的问题
B
Blog
D
DataBreaches.Net

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
Share Your Local Laravel App on a Public URL Without Mixe...
Nasrul Hazim Bin Mohamad · 2026-06-27 · via DEV Community

TL;DR

  • Exposing a local Laravel app over a public HTTPS tunnel breaks two ways: assets load from your localhost (teammate sees no CSS), and php artisan serve speaks plain HTTP behind the HTTPS proxy, so Livewire/Flux emit http:// URLs that the browser blocks as mixed content.
  • Fix the protocol with trustProxies(at: '*'), and fix the asset origin by pointing APP_URL + ASSET_URL at the tunnel URL.
  • I wrapped the whole thing in a composer share command that builds assets, opens the tunnel, rewrites .env, and restores it on exit. It's in cleaniquecoders/kickoff.

The problem

You want a teammate to click through your work-in-progress without deploying. The classic move: cloudflared tunnel (or ngrok) gives you a public https://... URL pointing at your local php artisan serve.

Then two things go wrong.

Symptom Cause Fix
Teammate sees raw HTML, no styling @vite points at the Vite dev server on your localhost (public/hot exists) Build assets, delete public/hot
Console: "mixed content blocked", random 419s Proxy is HTTPS but artisan serve is HTTP → request()->isSecure() is falsehttp:// asset/script URLs Trust the proxy + set ASSET_URL

Fix 1: trust the proxy

The tunnel terminates TLS and forwards plain HTTP to your app with an X-Forwarded-Proto: https header. Laravel ignores that header unless you tell it the proxy is trustworthy.

// bootstrap/app.php
->withMiddleware(function (Middleware $middleware) {
    // Honour X-Forwarded-Proto from the tunnel so isSecure() is true
    // and Livewire/Flux emit https:// URLs (no mixed-content blocks).
    $middleware->trustProxies(at: '*');
    // ...
})

at: '*' trusts any proxy. That's fine for a throwaway tunnel on your own machine. In production, trust specific load-balancer IPs instead — a wildcard there lets a client spoof the forwarded headers.

Fix 2: point assets at the tunnel

Even with HTTPS detected, @vite and asset helpers resolve against APP_URL. If that's still http://localhost, the public visitor's browser tries to fetch your localhost. So rewrite both to the tunnel URL once it's up:

# wait for the tunnel to print its public https URL, then:
set_env APP_URL   "$PUBLIC_URL"
set_env ASSET_URL "$PUBLIC_URL"
php artisan config:clear

The one habit that saves you: back up .env first and restore it on exit, so a throwaway URL never gets left behind in your config.

ENV_BACKUP="$(mktemp)"; cp .env "$ENV_BACKUP"

cleanup() {
    rm -f public/hot
    cp "$ENV_BACKUP" .env   # restore APP_URL / ASSET_URL verbatim
    php artisan config:clear >/dev/null 2>&1 || true
}
trap cleanup EXIT
trap 'exit 130' INT TERM

One command

Wrapped together, composer share does the boring sequence every time: npm run buildrm public/hotphp artisan serve → open a Cloudflare (or ngrok) tunnel → scrape the public URL → set APP_URL/ASSET_URL → stream output until Ctrl+C → restore .env. Cloudflare's quick tunnel needs no account, so it's the default.

composer share
  │
  ├─ npm run build         (real assets, not the dev server)
  ├─ rm public/hot         (stop @vite pointing at localhost)
  ├─ php artisan serve     (:8000)
  ├─ cloudflared tunnel    -> https://xxxx.trycloudflare.com
  ├─ set APP_URL+ASSET_URL -> that url, config:clear
  └─ Ctrl+C -> restore .env, drop public/hot

Takeaway

The tunnel was never the hard part — the protocol mismatch was. Trust the forwarded proto, anchor your asset URL to the public host, and always restore .env. Bundle it into one command so "send me a link" takes five seconds, not five minutes of debugging blank CSS.

Code lives in cleaniquecoders/kickoff.