You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Laravel 5.5中使用守卫实现用户与管理员原生多认证?

Fixing Laravel Multi-Authentication for Users & Admins + Guest Middleware Cleanup

Hey there! You’ve already got the core pieces in place for multi-auth, so let’s iron out the remaining logic issues and fix that hardcoded route problem in your guest middleware.


First: Double-Check Your Auth Configuration

From what you shared, your config/auth.php should have separate guards and providers for users and admins. Let’s confirm the key sections are set up correctly (this avoids common edge cases):

// config/auth.php
return [
    'defaults' => [
        'guard' => 'web', // Keep default as user unless you want admin to be default
        'passwords' => 'users',
    ],

    'guards' => [
        'web' => [
            'driver' => 'session',
            'provider' => 'users',
        ],
        'admin' => [
            'driver' => 'session',
            'provider' => 'admins',
        ],
    ],

    'providers' => [
        'users' => [
            'driver' => 'eloquent',
            'model' => App\Models\User::class,
        ],
        'admins' => [
            'driver' => 'eloquent',
            'model' => App\Models\Admin::class,
        ],
    ],

    'passwords' => [
        'users' => [
            'provider' => 'users',
            'table' => 'password_resets',
            'expire' => 60,
        ],
        'admins' => [
            'provider' => 'admins',
            'table' => 'admin_password_resets', // Don't forget to create this migration!
            'expire' => 60,
        ],
    ],
];

And make sure your Admin model explicitly sets its guard:

// App/Models/Admin.php
class Admin extends Authenticatable
{
    use Notifiable;

    protected $guard = 'admin'; // Critical for linking the model to its guard

    protected $fillable = ['name', 'email', 'password'];
    protected $hidden = ['password', 'remember_token'];
}

Fixing Common Multi-Auth Logic Issues

If you’re stuck on login/logout, protected routes, or controller logic, here’s how to structure it cleanly:

1. Create Separate Auth Controllers

Generate an admin auth controller to handle admin-specific login/logout:

php artisan make:controller Auth/AdminAuthController

Add this logic to the controller (it mirrors the default user auth but uses the admin guard):

// App/Http/Controllers/Auth/AdminAuthController.php
namespace App\Http\Controllers\Auth;

use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Auth;

class AdminAuthController extends Controller
{
    public function showLoginForm()
    {
        return view('auth.admin-login'); // Create this view in resources/views/auth
    }

    public function login(Request $request)
    {
        $request->validate([
            'email' => 'required|email',
            'password' => 'required|string',
        ]);

        // Attempt to authenticate with the admin guard
        if (Auth::guard('admin')->attempt($request->only('email', 'password'), $request->filled('remember'))) {
            $request->session()->regenerate();
            return redirect()->intended(route('admin.dashboard'));
        }

        return back()->withErrors([
            'email' => 'Invalid admin credentials.',
        ]);
    }

    public function logout(Request $request)
    {
        Auth::guard('admin')->logout();
        $request->session()->invalidate();
        $request->session()->regenerateToken();

        return redirect()->route('admin.login');
    }
}

2. Define Clean, Guard-Specific Routes

Group your admin routes to keep them organized, and apply the correct middleware:

// routes/web.php
use App\Http\Controllers\Auth\AdminAuthController;
use App\Http\Controllers\Auth\AuthController;
use App\Http\Controllers\AdminController;

// User Auth Routes (default web guard)
Route::middleware('guest:web')->group(function () {
    Route::get('/login', [AuthController::class, 'showLoginForm'])->name('login');
    Route::post('/login', [AuthController::class, 'login']);
});

Route::middleware('auth:web')->group(function () {
    Route::post('/logout', [AuthController::class, 'logout'])->name('logout');
    Route::get('/dashboard', [UserController::class, 'dashboard'])->name('user.dashboard');
});

// Admin Auth Routes
Route::prefix('admin')->name('admin.')->group(function () {
    Route::middleware('guest:admin')->group(function () {
        Route::get('/login', [AdminAuthController::class, 'showLoginForm'])->name('login');
        Route::post('/login', [AdminAuthController::class, 'login']);
    });

    Route::middleware('auth:admin')->group(function () {
        Route::post('/logout', [AdminAuthController::class, 'logout'])->name('logout');
        Route::get('/dashboard', [AdminController::class, 'dashboard'])->name('dashboard');
    });
});

Fixing the Hardcoded Guest Middleware

The default RedirectIfAuthenticated middleware (your guest middleware) probably has hardcoded routes. Let’s update it to dynamically redirect based on the authenticated guard:

// App/Http/Middleware/RedirectIfAuthenticated.php
namespace App\Http\Middleware;

use Closure;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Auth;

class RedirectIfAuthenticated
{
    public function handle(Request $request, Closure $next, ...$guards)
    {
        $guards = empty($guards) ? [null] : $guards;

        foreach ($guards as $guard) {
            if (Auth::guard($guard)->check()) {
                // Redirect to the correct dashboard based on the guard
                $route = match ($guard) {
                    'admin' => 'admin.dashboard',
                    default => 'user.dashboard', // Or your default user route
                };

                return redirect()->route($route);
            }
        }

        return $next($request);
    }
}

Now when you use middleware('guest:admin') or middleware('guest:web'), the middleware will redirect to the appropriate dashboard instead of using a hardcoded route.


Extra Tips to Avoid Headaches

  • Password Resets: If you need admin password reset, generate a dedicated controller and run a migration for admin_password_resets (matching the passwords config above).
  • Authorization: Use Laravel’s policies or gates to separate user/admin permissions clearly.
  • Views: Make sure admin login forms point to route('admin.login') instead of the user login route.

内容的提问来源于stack exchange,提问作者Latheesan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:45:38