laravelxmlhttprequestpostmanlaravel-authenticationlaravel-fortify

Laravel Fortify doesn't respond with HTTP code but with actual routes, even if I send the registration request as an XHR one


Context

With Postman, I send the following fields in order to register a user in the db, to the URL http://mywebsite/register:

According to the documentation https://laravel.com/docs/8.x/fortify#registration (from which I found the above fields), Fortify already defines the route register so I don't need to define it myself.

According to the documentation, and to my needs, I don't need to create a registration form: I directly use Postman to send these registration data to Laravel Fortify's route /register as XHR POST request data. Moreover, I don't need Fortify to return views so I've disabled them (https://laravel.com/docs/8.x/fortify#disabling-views). Indeed, I just wait for HTTP code response that I will see in Postman's return data (see below).

What Fortify should return

Since I've disabled the views AND since I send a XHR POST Request (in Postman I'm sending this HTTP header along with the registration request: X-Requested-With = XMLHttpRequest):

If the registration attempt is successful, Fortify will redirect the user to the URI configured via the home configuration option within your application's fortify configuration file. If the login request was an XHR request, a 200 HTTP response will be returned.

If the request was not successful, the user will be redirected back to the registration screen and the validation errors will be available to you via the shared $errors Blade template variable. Or, in the case of an XHR request, the validation errors will be returned with a 422 HTTP response.

(https://laravel.com/docs/8.x/fortify#registration)

What Fortify actually returns

It correctly registers the user. But the results I see in Postman is a Symfony\\Component\\HttpKernel\\Exception\\NotFoundHttpException. Indeed, Fortify is trying to reach the home view.

Question

Why does Fortify still seem to try to reach returned views routes (not defined because I don't need them), since my request is correctly an XHR POST one and since I've disabled the views in the Fortify config file?


Solution

  • I think I've found something "interesting" in the Fortify doc (https://laravel.com/docs/8.x/fortify#registration). Something is incomplete there. I think I've found what is missing in the docs!

    I explain.

    In my case, a phone app shows a registration form. It sends the Fortify's registration required fields like email, password, confirmation_password, ... to the URL <LaravelSite>/register which is defined by Fortify. Fortify successfully register the user and redirects him to the home route. However, I don't have defined any home route since that as you have understood, this Laravel site is an API. Results => I have this error: Symfony\\Component\\HttpKernel\\Exception\\NotFoundHttpException.

    I've followed the docs: I've disabled the views (in the Fortify config file). I've correctly specified that the request sent by the phone app (in reality, by Postman) is a XHR Request (indeed, I've sent the header X-Requested-With = XMLHttpRequest). So Fortify should return me a HTTP Code (200 here) instead of trying to return me the home URL.

    What is missing in the doc? =====>>>> the middleware RedirectIfAuthenticated is executed. In its handle method there is a redirection: return redirect(RouteServiceProvider::HOME);. In order to make Fortify work correctly, this line must be disabled by commenting it.

    The Fortify docs should contains something like the above sentence.

    A PR or an issue should be created on their Github repository.

    EDIT: we must also send this HTTP header: Accept: application/json (otherwise in case of registration success, it will still show a 404)