Laravel批量赋值密码存明文问题及解决方法
Laravel 密码批量赋值与加密解决方案
Hey fellow Laravel developers! If you've run into issues where plaintext passwords are ending up in your MySQL database when handling password assignment (especially with mass assignment), here's a straightforward fix:
The Common Mistake
If you're doing something like this directly:
$example->password = $inputs['password'];
You'll end up storing plaintext passwords in your database—super unsafe!
The Correct Approach
Follow these steps to ensure passwords are properly hashed before storage:
- First, hash the password from your input array:
$inputs['password'] = Hash::make($inputs['password']); - Verify the hash works (optional but recommended) using
Hash::check()to confirm the plaintext password matches the hashed version:
This should returndd(Hash::check('your-plaintext-password', $inputs['password']));trueif the hash was generated correctly. - Now you can safely assign the values (either via mass assignment like
$example->fill($inputs)->save()or direct assignment) and the password will be stored as a secure hash in the database.
Just a quick reminder: Make sure your model's $fillable property includes the password field if you're using mass assignment—otherwise Laravel will block that field from being set!
内容的提问来源于stack exchange,提问作者Jud3v Digital
相关产品推荐
相关产品推荐

