Laravel Breeze取消密码哈希后登录失败求助
解决Laravel Breeze取消密码哈希后登录失败的问题
核心原因
Laravel默认登录验证逻辑(Auth::attempt)会自动对输入密码做哈希处理,再和数据库值对比。你取消了注册时的密码哈希,数据库存的是明文密码,导致验证时哈希后的输入密码与明文不匹配,因此提示凭证错误。
解决步骤
1. 修改登录验证逻辑
找到app\Http\Requests\Auth\LoginRequest.php,替换authenticate方法:
public function authenticate() { $this->ensureIsNotRateLimited(); // 手动查询用户,直接对比明文密码 $user = \App\Models\User::where('email', $this->email)->first(); if (! $user || $user->password !== $this->password) { \Illuminate\Support\Facades\RateLimiter::hit($this->throttleKey()); throw \Illuminate\Validation\ValidationException::withMessages([ 'email' => __('auth.failed'), ]); } \Illuminate\Support\Facades\Auth::login($user, $this->boolean('remember')); \Illuminate\Support\Facades\RateLimiter::clear($this->throttleKey()); }
2. 修复迁移错误
如果迁移报错,检查database/migrations/xxxx_xx_xx_xxxxxx_create_users_table.php中的password字段定义,确保它能容纳明文密码(默认的$table->string('password');即varchar(255)足够)。若之前执行过迁移,需回滚后重新执行:
php artisan migrate:rollback php artisan migrate
(注意:回滚会清空用户表数据,操作前请备份)
重要提醒
绝对不要在生产环境使用明文密码,这会导致用户密码泄露,严重违反安全规范。取消密码哈希仅适合本地测试场景,正式项目必须保留Hash::make()处理密码。
内容的提问来源于stack exchange,提问作者John Lyons
相关产品推荐
相关产品推荐

