You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel API创建调用即自动验证用户邮箱的端点报错求助

问题根因

你之前编写的代码存在几个核心错误,导致返回空message:

  1. 第一次尝试的路由没有声明id、hash路径参数,控制器调用$request->route('id')返回空值,抛出未携带自定义信息的AuthorizationException,最终返回空message
  2. 第二次、第三次尝试重复声明auth中间件,和外层的auth:sanctum冲突,且API场景下默认的EmailVerificationRequest会自动跳转网页而非返回JSON
  3. 第三次尝试的控制器未引入App\Models\User类,且最后返回跳转响应,API调用时无法正常解析

完整可运行实现方案

1. 路由配置(routes/api.php)

use Illuminate\Support\Facades\Route;
use App\Http\Controllers\Auth\VerificationController;

Route::group(['middleware' => ['auth:sanctum', 'signed']], function (){    
    Route::get('/email/verify/{id}/{hash}', [VerificationController::class, 'verify'])
        ->name('verification.verify');
});

// 可选:补充重发验证邮件的接口
Route::post('/email/verification-notification', [VerificationController::class, 'resend'])
    ->middleware(['auth:sanctum', 'throttle:6,1'])
    ->name('verification.send');

2. 控制器代码(app/Http/Controllers/Auth/VerificationController.php)

<?php
namespace App\Http\Controllers\Auth;

use App\Http\Controllers\Controller;
use App\Models\User;
use Illuminate\Auth\Events\Verified;
use Illuminate\Http\Request;

class VerificationController extends Controller
{
    public function __construct()
    {
        $this->middleware('throttle:6,1')->only('verify', 'resend');
    }

    /**
     * 完成邮箱验证
     */
    public function verify(Request $request, $id, $hash)
    {
        // 校验链接签名合法性
        if (! $request->hasValidSignature()) {
            return response()->json([
                'message' => '验证链接已失效或不合法'
            ], 403);
        }

        $user = User::findOrFail($id);

        // 校验hash与用户邮箱是否匹配
        if (! hash_equals((string) $hash, sha1($user->getEmailForVerification()))) {
            return response()->json([
                'message' => '邮箱验证信息不匹配'
            ], 403);
        }

        // 校验是否已完成验证
        if ($user->hasVerifiedEmail()) {
            return response()->json([
                'message' => '邮箱已完成验证,无需重复操作'
            ], 200);
        }

        // 标记邮箱为已验证
        if ($user->markEmailAsVerified()) {
            event(new Verified($user));
        }

        return response()->json([
            'message' => '邮箱验证成功'
        ], 200);
    }

    /**
     * 重发验证邮件
     */
    public function resend(Request $request)
    {
        if ($request->user()->hasVerifiedEmail()) {
            return response()->json([
                'message' => '邮箱已完成验证,无需重复发送'
            ], 400);
        }

        $request->user()->sendEmailVerificationNotification();

        return response()->json([
            'message' => '验证邮件已重新发送'
        ], 200);
    }
}

3. 配套配置要求

  • 确保User模型已实现MustVerifyEmail接口:
use Illuminate\Contracts\Auth\MustVerifyEmail;

class User extends Authenticatable implements MustVerifyEmail
{
    // 原有模型代码保持不变
}
  • 若需要修改验证邮件内的链接为API接口路径,可在App\Providers\AuthServiceProvider的boot方法中添加自定义逻辑:
use Illuminate\Auth\Notifications\VerifyEmail;
use Illuminate\Support\Facades\URL;

public function boot()
{
    $this->registerPolicies();

    VerifyEmail::createUrlUsing(function ($notifiable) {
        return URL::temporarySignedRoute(
            'verification.verify',
            now()->addMinutes(60), // 验证链接有效期可自行调整
            [
                'id' => $notifiable->getKey(),
                'hash' => sha1($notifiable->getEmailForVerification()),
            ]
        );
    });
}

内容的提问来源于stack exchange,提问作者Tracy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.02 16:54:03