*/ protected $except = [ 'chat_post', 'chat_post/*', // Apple Sign In removed — no special CSRF exception required ]; }