Laravel新手开发登录注册功能时遭遇POST方法不支持错误求助
Let's break down your problem step by step and fix it properly—this error is common for Laravel beginners, and we'll cover all the underlying issues beyond just the route mismatch.
Core Error Cause
The immediate issue is that your login form submits a POST request to /hot_smoke_login, but you don't have a POST route defined for that endpoint. Worse, you've defined two duplicate GET routes for /hot_smoke_login, which means the second one (match2 method) overrides the first, and there's no way to handle the POST submission.
Step 1: Fix Your Route Configuration
First, clean up your routes to properly separate "show form" and "handle submission" actions. Update your routes/web.php to:
use App\Http\Controllers\HotSmokeController; // Note the corrected class name (camelCase) // Registration routes Route::get('sign-Up', [HotSmokeController::class, 'signup'])->name('signup'); Route::post('sign-Up', [HotSmokeController::class, 'store'])->name('signup.store'); // Login routes Route::get('hot_smoke_login', [HotSmokeController::class, 'login'])->name('login'); Route::post('hot_smoke_login', [HotSmokeController::class, 'match2'])->name('login.submit');
Key fixes here:
- Added unique names to routes (makes linking/redirecting easier)
- Created a dedicated
POSTroute for login submissions - Corrected the controller class name to follow Laravel's PSR-4 standards (camelCase, suffixed with
Controller)
Step 2: Fix Your Blade Login Form
Your form has critical missing pieces that will break functionality even after fixing routes:
- Missing CSRF Token: Laravel blocks all POST requests without a CSRF token for security.
- No
nameattributes on inputs:Request::input()uses the input'sname(notid) to fetch values. - Unspecified form
action: The form doesn't know where to send the POST request.
Update your login form section to:
<form method="post" id="login" action="{{ route('login.submit') }}"> @csrf <!-- Required CSRF token --> <div class="form-group first d-flex flex-column"> <label class="primary-color" for="username">Email</label> <input type="email" class="email" id="username" name="email"> <!-- Added name="email" --> </div> <div class="form-group last mb-3 d-flex flex-column"> <label class="primary-color" for="password">Password</label> <input type="password" class="email" id="password" name="password"> <!-- Added name="password" --> </div> <!-- Keep your existing checkbox, link, and error message here --> @if(session('error')) <small class="text-danger">{{ session('error') }}</small> @endif <button type="submit" class="email-button">Log In</button> </form>
Step 3: Fix Your Controller Issues
Your controller has several security and functionality problems—let's clean those up:
namespace App\Http\Controllers; use Illuminate\Http\Request; use Illuminate\Support\Facades\DB; use Illuminate\Support\Facades\Hash; // Follow Laravel naming conventions: camelCase class name with Controller suffix class HotSmokeController extends Controller { // Show login page public function login() { return view('hot_smoke_login'); } // Show registration page public function signup() { return view('sign-Up'); } // Show dashboard (you might want to add authentication checks here later) public function login2() { return view('dashboard'); } // Handle registration submission public function store(Request $request) { // Fetch input values using the injected Request instance (better practice than the facade) $uname = $request->input('name'); $uemail = $request->input('email'); $unumber = $request->input('number'); $uaddress = $request->input('address'); $upass = $request->input('password'); // Fix 1: Use Laravel's query builder to avoid SQL injection (never use unprepared with user input!) // Fix 2: Hash passwords (never store plain text passwords!) DB::table('customers')->insert([ 'name' => $uname, 'email' => $uemail, 'number' => $unumber, 'address' => $uaddress, 'password' => Hash::make($upass) ]); return redirect()->route('login'); // Use named routes for cleaner redirects } // Handle login submission public function match2(Request $request) { $uemail = $request->input('email'); $upass = $request->input('password'); // Fix: You were querying the `users` table, but inserting into `customers`—use the correct table! $customer = DB::table('customers')->where('email', $uemail)->first(); if ($customer) { // Fix: Use Hash::check() to compare plain text password against hashed stored password if (Hash::check($upass, $customer->password)) { // Optional: Add Laravel's built-in authentication here (e.g., Auth::loginUsingId($customer->id)) return view('dashboard'); } else { return view('hot_smoke_login')->with('error', 'Password does not match'); } } else { return view('hot_smoke_login')->with('error', 'Email not found in our system'); } } }
Key controller fixes:
- Removed unsafe
DB::unprepared()(prevents SQL injection) - Added password hashing (critical for security)
- Fixed table name mismatch (you were inserting into
customersbut queryingusers) - Used dependency injection for the
Requestclass (better practice than the facade) - Followed Laravel naming conventions for the controller class
Final Checks
- Make sure your
customerstable has the correct columns (name,email,number,address,password). - Clear your route cache with
php artisan route:clearto apply route changes. - Test both registration and login flows to ensure everything works.
内容的提问来源于stack exchange,提问作者usama iftikhar

