You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel中点击密码初始化邮件链接触发Attempt to read property 'needs_password' on null错误的技术求助

Fixing "Attempt to read property 'needs_password' on null" Error in Password Reset Flow

Alright, let's break down exactly what's causing this error and walk through the fixes:

Root Cause

The error happens because your code can't find a valid User instance when the user clicks the password reset link. This stems from a few key issues:

  • Your signed route doesn't include a user identifier, so Laravel can't load the correct user record
  • You aren't setting needs_password to true when creating new users (it defaults to false)
  • Your middleware is looking for a route parameter named users that doesn't exist in your route definition

Step 1: Update User Creation & Signed Route Generation

In your UserController, you need to do two critical things: enable the password reset requirement for new users, and pass the user's ID to the signed route so the backend knows which user is attempting to reset their password.

Update this section of your code:

$user = new User;
$user->name = $request->name;
$user->email = $request->email;
$user->join_date = $todayDate;
$user->role_name = $request->role_name;
$user->status = $request->status;
$user->avatar = $image;
$user->needs_password = true; // Add this line to flag the user needs a password reset
$user->password = $pass;
$user->save();

// Pass the user ID to the signed route so we can load their record later
$url = URL::signedRoute('password-redirect', ['user' => $user->id]);

DB::commit();
Mail::send('auth.mail', [ 'url' => $url], function($message) use ($request) {
    $message->from('noreply@taskproph.com');
    $message->to($request->email);
    $message->subject('Reset Password Notification');
});

Step 2: Fix Your Route Configuration

Your current route doesn't include a user parameter, so Laravel can't automatically inject the User instance. Update your routes to include the {user} parameter (this uses Laravel's implicit model binding to load the correct user):

Route::controller(PasswordController::class)->group(function () {
    // Add {user} parameter to link the route to a specific user
    Route::get('/password-redirect/{user}', 'create')->middleware('signed','needs_password')->name('password-redirect');
    Route::post('/create-password/{user}', 'store')->middleware('needs_password')->name('create-password');
});

Note: Ensure your middleware is registered correctly in app/Http/Kernel.php under $routeMiddleware with the key needs_password pointing to your middleware class.

Step 3: Correct the Needs_Password Middleware

Your middleware is looking for a route parameter named users, but your route uses user. Fix that, and add a check to make sure the user exists before accessing its properties:

public function handle(Request $request, Closure $next) {
    // Get the user from the route parameter (matches {user} in the route)
    $user = $request->route('user');

    // First check if the user exists to avoid null errors
    if (!$user) {
        abort(404, 'User not found');
    }

    // Then verify they need to reset their password
    if ($user->needs_password) {
        return $next($request);
    }

    abort(400, 'Password reset is not required for this account');
}

Step 4: Update PasswordController's Create Method

You're currently returning the email template (auth.mail) instead of the password reset form view. Update this to return your actual reset form, and pass the user to it:

public function create(User $user) {
    // Extra safety check to ensure the user needs a password reset
    abort_unless($user->needs_password, 400);
    
    // Replace 'auth.reset-password' with your actual password reset form view name
    return view('auth.reset-password', compact('user'));
}

Step 5: Verify Your Email Template

Make sure your auth.mail template is using the correct URL variable:

<p>Click the link below to reset your password:</p>
<a href="{{ $url }}">Reset Password</a>

After making all these changes, when a new user is created:

  1. Their needs_password flag is set to true
  2. The email sends a signed link containing their user ID
  3. When they click the link, Laravel loads the correct User instance via implicit binding
  4. The middleware validates they need a password reset and allows access to the form

This should completely eliminate the "Attempt to read property 'needs_password' on null" error.

内容的提问来源于stack exchange,提问作者Jay-ar Cristobal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 14:27:42