Skip to content

Signed URLs

By default anyone can request any combination the allowlists permit. With signed URLs the endpoint accepts only URLs generated by your backend.

IMAGEPRESET_SIGNED_URL=true

or 'route' => ['signed' => true] in the config.

  • imagepreset_url(), Imagepreset::url() and @imagepreset() generate URLs with URL::signedRoute():

    https://example.com/imagepreset?fm=webp&src=photo.jpg&w=800&signature=5f2c…
  • The route gets Laravel’s signed middleware. A missing, wrong or tampered signature returns 403.

  • The signature covers the whole query string, so a client can’t change w, add parameters or swap src.

  • The URLs have no expires — they are permanent and safe to cache in a CDN.

  • The signature is made with APP_KEY. Rotating the key invalidates every URL already in HTML, caches and search indexes.

Allowlists still apply to signed URLs. To generate sizes outside them, add the sizes or use named presets — see the note on trusted bypass below.

  • Hand-written URLs stop working. /imagepreset?src=… in HTML, CSS, a frontend app or a mobile client returns 403. Everything must go through the helper on the server.
  • The host is part of the signature. Laravel validates the signature against the URL of the incoming request. If a CDN or proxy forwards requests with a different Host or scheme than the one the URL was generated for, every request fails with 403 — configure trusted proxies and keep the host the same.
  • The setting is read when the route is registered. Changing route.signed at runtime changes generated URLs but not the middleware.