You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel 10自定义Guard时出现认证错误,请求协助解决

问题分析

自定义Guard认证失败的核心原因是Laravel默认认证逻辑依赖password字段作为密码验证字段,而你的StaffModel中密码存储在staff_password字段,同时认证使用的用户名是staff_email,需要调整模型的认证相关方法适配自定义字段。

解决方案

1. 修改StaffModel.php,重写认证方法

在StaffModel类中添加两个方法,指定自定义的用户名和密码字段:

<?php

namespace App\Models;

use Illuminate\Database\Eloquent\Factories\HasFactory;
use Illuminate\Foundation\Auth\User as Authenticatable;
use Illuminate\Notifications\Notifiable;

class StaffModel extends Authenticatable
{
    use HasFactory, Notifiable;

    protected $table = 'tbl_staff';
    protected $primaryKey = 'staff_id';
    protected $fillable = [
        "staff_name",
        "staff_birthday",
        "staff_gender",
        "staff_phone",
        "staff_email",
        "staff_password",
        "staff_address",
        "staff_position",
        "staff_role",
        "staff_status",
    ];

    protected $hidden = [
        'staff_password',
        'remember_token',
    ];

    protected $casts = [
        'email_verified_at' => 'datetime',
    ];

    // 指定认证使用的用户名字段
    public function getAuthIdentifierName()
    {
        return 'staff_email';
    }

    // 指定认证使用的密码字段
    public function getAuthPassword()
    {
        return $this->staff_password;
    }
}

2. 优化登录方法的凭证格式(可选)

为了贴合Laravel默认逻辑,可将请求中的staff_password重命名为password,避免字段名混淆:

public function staff_login(Request $request)
{
    $validated = $request->validate([
        'staff_email' => 'required|email',
        'staff_password' => 'required',
    ]);

    // 转换密码字段名为Laravel默认的password
    $credentials = [
        'staff_email' => $validated['staff_email'],
        'password' => $validated['staff_password'],
    ];

    if (Auth::guard('staff')->attempt($credentials)) {
        return response()->json([
            'success' => true,
            'message' => 'Login successful.',
        ]);
    } else {
        return response()->json([
            'success' => false,
            'message' => 'Invalid credentials.',
        ]);
    }
}

3. 验证密码哈希一致性(调试用)

若仍失败,可临时添加调试代码确认密码哈希是否匹配:

// 在staff_login方法中加入,调试后删除
$staff = \App\Models\StaffModel::where('staff_email', $validated['staff_email'])->first();
if ($staff) {
    dd($staff->staff_password, bcrypt($validated['staff_password']));
}
验证步骤
  1. 清除Laravel缓存:php artisan cache:clear
  2. 使用正确的邮箱密码重新登录
  3. 确认数据库中staff_email准确,staff_password为有效的bcrypt哈希值

内容的提问来源于stack exchange,提问作者Thành Ý

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 03:34:56