Skip to content

Trusted bypass

Some pages need sizes that are not in the allowlists — a Blade layout with dozens of card sizes, several domains with different designs. Trusted bypass lets URLs generated on the server skip the allowlists, while requests built by anyone else are still validated.

IMAGEPRESET_TRUSTED_BYPASS=true

Pass true as the third argument:

imagepreset_url('photo.jpg', ['w' => 756, 'h' => 380, 'fm' => 'webp'], true);
Imagepreset::url('photo.jpg', ['w' => 756, 'h' => 380], true);
<img src="@imagepreset('photo.jpg', ['w' => 756, 'h' => 380, 'fm' => 'webp'], true)" alt="">

The URL gets a _t parameter — the first 16 hex characters of an HMAC-SHA256 of the other parameters, keyed with APP_KEY:

https://example.com/imagepreset?_t=625ecf4b5d9bfc22&fm=webp&h=380&src=photo.jpg&w=756

With trusted_bypass = false the third argument is ignored and no token is added.

CheckSkipped with a valid _t
allowed_sizes, allowed_widths, allowed_heightsyes
allowed_qualitiesyes
allowed_fitsyes
allowed_formatsyes
allowed_orientations, blur_max, sharp_max, crop/bg formatno
w/h between 1 and 20000no
fit requires w or hno
src: path traversal, remote host allowlist, SSRF checksno
max_image_pixelsno

A wrong or tampered token is not an error by itself — the request is validated like any other and passes only if it fits the allowlists.

  • Changing, adding or removing any parameter invalidates the token — it is computed over the whole query string except _t.
  • _t is excluded from the cache key, so a trusted and a plain request for the same parameters share one file.
  • Rotating APP_KEY invalidates all tokens; affected URLs then fall back to normal validation.
  • Keep it off on sites where image URLs are built by clients (public APIs, SPAs): the bypass is only useful for URLs your server renders.
  • _t must be exactly 16 characters; any other length is a validation error (404).