Laravel多域名应用实现:不同域名对应不同登录后共享代码基
可行实现方案:单一代码基下的域名感知认证
完全可以实现你的需求,核心是基于域名的路由分发+统一认证服务层,不需要拆分应用,所有业务逻辑、控制器、视图完全共享,仅在登录环节根据域名切换认证方式。以下是具体实现步骤:
1. 域名路由配置:指向同一应用实例
首先确保domain1.com和domain2.com都指向你的应用服务器(比如Nginx配置两个server块,root指向同一代码目录)。然后在应用框架的路由层,根据请求的Host头区分登录入口:
- 给
domain1.com配置邮箱密码登录的路由(对应标准认证脚手架) - 给
domain2.com配置LDAP专属登录路由
以Django为例的路由示例:
from django.conf.urls import url from .views import EmailLoginView, LdapLoginView urlpatterns = [ url(r'^login$', EmailLoginView.as_view(), name='email_login', host='domain1.com'), url(r'^login$', LdapLoginView.as_view(), name='ldap_login', host='domain2.com'), ]
2. 抽象统一认证层,隔离不同登录逻辑
为了避免代码耦合,抽象一个通用的认证接口,实现两种不同的认证器:
- EmailPasswordAuthenticator:处理邮箱密码校验,调用标准认证接口生成会话
- LdapAuthenticator:先校验LDAP凭证,成功后查询数据库获取用户信息,再调用标准认证接口完成登录并分配标准角色
以Java Spring为例的伪代码:
public interface Authenticator { UserDetails authenticate(String identifier, String credential); } // 邮箱密码认证实现 @Component("emailAuthenticator") public class EmailPasswordAuthenticator implements Authenticator { @Override public UserDetails authenticate(String email, String password) { User user = userRepository.findByEmail(email); if (passwordEncoder.matches(password, user.getPassword())) { user.setRole("standard"); return user; } throw new BadCredentialsException("密码错误"); } } // LDAP认证实现 @Component("ldapAuthenticator") public class LdapAuthenticator implements Authenticator { @Autowired private LdapTemplate ldapTemplate; @Autowired private UserRepository userRepository; @Override public UserDetails authenticate(String username, String password) { // 1. 校验LDAP凭证 boolean isLdapValid = ldapTemplate.authenticate("ou=users,dc=example,dc=com", "uid={0}", username, password); if (!isLdapValid) { throw new BadCredentialsException("LDAP验证失败"); } // 2. 从数据库获取用户额外信息 User user = userRepository.findByLdapUsername(username); // 3. 分配标准角色 user.setRole("standard"); return user; } }
3. 统一会话管理,共享后续业务流程
无论哪种登录方式成功后,都使用框架的统一认证机制生成会话(比如Session、JWT),会话中只存储用户ID、角色等通用信息,不记录登录来源。后续所有请求的身份校验都基于这个统一会话,确保controllers、views等业务组件完全共享,无需区分用户是通过哪个域名登录的。
关键注意事项
- Cookie跨域名共享:如果两个域名是同主域名的子域名(比如
a.example.com和b.example.com),可以设置Cookie的Domain为.example.com实现会话共享;如果是完全独立的顶级域名,建议使用JWT令牌(存储在前端localStorage),或者用Redis等共享存储维护会话状态。 - 配置可扩展性:可以把域名与认证器的映射关系放到配置文件,后续新增域名和认证方式时只需修改配置,无需改动核心代码。
- 避免模块拆分:不要按域名划分业务模块,所有业务逻辑、视图、控制器都放在同一代码目录下,仅登录入口和认证实现分离。
这种方案完全符合你的需求:同一代码基,不同域名对应不同登录方式,登录后共享所有业务组件,不需要拆分应用。
内容的提问来源于stack exchange,提问作者andy bee
相关产品推荐
相关产品推荐

