Signed URLs
By default anyone can request any combination the allowlists permit. With signed URLs the endpoint accepts only URLs generated by your backend.
IMAGEPRESET_SIGNED_URL=trueor 'route' => ['signed' => true] in the config.
How it works
Section titled “How it works”-
imagepreset_url(),Imagepreset::url()and@imagepreset()generate URLs withURL::signedRoute():https://example.com/imagepreset?fm=webp&src=photo.jpg&w=800&signature=5f2c… -
The route gets Laravel’s
signedmiddleware. A missing, wrong or tampered signature returns 403. -
The signature covers the whole query string, so a client can’t change
w, add parameters or swapsrc. -
The URLs have no
expires— they are permanent and safe to cache in a CDN. -
The signature is made with
APP_KEY. Rotating the key invalidates every URL already in HTML, caches and search indexes.
Allowlists still apply to signed URLs. To generate sizes outside them, add the sizes or use named presets — see the note on trusted bypass below.
Things to watch
Section titled “Things to watch”- Hand-written URLs stop working.
/imagepreset?src=…in HTML, CSS, a frontend app or a mobile client returns 403. Everything must go through the helper on the server. - The host is part of the signature. Laravel validates the signature against the URL of the incoming request. If a CDN or proxy forwards requests with a different
Hostor scheme than the one the URL was generated for, every request fails with 403 — configure trusted proxies and keep the host the same. - The setting is read when the route is registered. Changing
route.signedat runtime changes generated URLs but not the middleware.