You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel10登录后跳转成功页面但无法获取已认证用户求助

Laravel 10登录后Dashboard页面无法获取认证用户问题排查

问题描述

提交正确凭证登录后成功跳转至dashboard页面,但在该页面执行dd(auth()->user())返回null;但在登录控制器中执行相同代码能返回完整用户数据。

相关代码与配置

登录控制器代码

public function authenticate(Request $request):RedirectResponse
{ 
    $request->validate([
        'email' => 'required',
        'password' => 'required',
    ]);

    if(Auth::attempt($credentials)){
        $request->session()->regenerate();
        return redirect()->intended('dashboard');
    }
    return redirect()->route("login")->withSuccess('Oppes! You have entered invalid credentials');
}

config/auth.php配置

'defaults' => [
    'guard' => 'web',
    'passwords' => 'users',
],
'guards' => [
    'web' => [
        'driver' => 'session',
        'redirectTo'=> 'dashboard',  //checked it doing comment and uncomment
        'provider' => 'users',
    ],
],
'providers' => [
    'users' => [
        'driver' => 'eloquent',
        'model' => App\Models\User::class,
    ],
],
'passwords' => [
    'users' => [
        'provider' => 'users',
        'table' => 'password_reset_tokens',
        'expire' => 60,
        'throttle' => 60,
    ],
],
'password_timeout' => 10800,

web.php路由

Route::get('/login',[Authenticationcontroller::class, 'login'])->name('login');
Route::post('/authenticate', [Authenticationcontroller::class, 'authenticate'])->name('authenticate');

User模型代码

public $incrementing = false;
protected $table = 'users';
protected $guard = 'web';
protected $primarykey = 'User_ID';
protected $keyType = 'string';
protected $fillable = ['First_Name','Last_Name', rest of the column ];
protected $hidden = [
    'password',
    'remember_token',
];

补充信息

  • 设置SESSION_DOMAIN=localhost后出现“419 page expired”错误;
  • 已修改RouteServiceProvider中的HOME常量为dashboard路由。

排查与解决步骤

1. 修复控制器中未定义的$credentials变量

登录控制器中Auth::attempt($credentials)的$credentials未从请求中获取,这会导致登录逻辑实际未生效:

public function authenticate(Request $request):RedirectResponse
{ 
    $request->validate([
        'email' => 'required',
        'password' => 'required',
    ]);

    // 新增:从请求中获取凭证
    $credentials = $request->only('email', 'password');

    if(Auth::attempt($credentials)){
        $request->session()->regenerate();
        return redirect()->intended('dashboard');
    }
    return redirect()->route("login")->withSuccess('Oppes! You have entered invalid credentials');
}

2. 修正User模型的属性拼写错误

模型中protected $primarykey应为protected $primaryKey(驼峰命名,K大写),Laravel依赖该属性识别主键,拼写错误会导致session存储的用户ID无法匹配模型,后续请求无法找回用户:

public $incrementing = false;
protected $table = 'users';
// 移除不必要的$guard属性,避免与配置冲突
// protected $guard = 'web';
protected $primaryKey = 'User_ID'; // 修正拼写
protected $keyType = 'string';
protected $fillable = ['First_Name','Last_Name', 'email', 'password', ...]; // 确保包含email和password字段
protected $hidden = [
    'password',
    'remember_token',
];

3. 确保Dashboard路由包含web中间件

session驱动的web guard依赖web中间件处理session,Dashboard路由必须包含该中间件(默认web路由组已包含,若单独定义需明确):

// 正确定义Dashboard路由
Route::get('/dashboard', [DashboardController::class, 'index'])
    ->middleware('web')
    ->name('dashboard');

如果路由在Route::middleware('web')组外定义,session不会被加载,导致auth()->user()返回null。

4. 调整SESSION配置避免419错误

本地开发时不要设置SESSION_DOMAIN=localhost,在.env文件中留空或设为null:

SESSION_DOMAIN=

同时确保config/session.php中:

  • driver设为file(本地开发推荐)
  • encrypt设为false
  • lifetime设置合理值(如120)

5. 检查Dashboard页面代码

  • 确保视图中没有意外调用Auth::logout()或清空session的代码;
  • 在Dashboard控制器的方法中先执行dd(auth()->user()),如果控制器能拿到数据但视图不能,检查视图是否有输出缓冲或session被意外销毁的逻辑。

内容的提问来源于stack exchange,提问作者Abdul Aziz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 09:44:57