Laravel 5.5自定义库中间件中$request->user()返回null问题求助
auth()->user() Returning Null in Custom Vendor Middleware Hey there! Let's break down why you're seeing null when calling auth()->user() or $request->user() in your custom middleware at /vendor/myCustom/src/Middleware/aMdl.php—even after setting up your service provider, routes, and registering the middleware in Kernel.php.
Core Root Cause: Middleware Execution Order
The main issue here is timing: your custom middleware is running before Laravel's authentication middleware finishes loading the user.
When you attach middleware in a controller's __construct() method, that middleware executes early in the request lifecycle—before the route is fully matched, and before Laravel's default auth middleware (which handles loading the authenticated user) runs. Even adding $this->middleware('auth') in the constructor doesn't fix this, because the authentication process hasn't completed by the time your custom middleware fires.
Step-by-Step Fixes
1. Ensure Your Middleware Runs After Authentication
Adjust your middleware registration to guarantee it executes after Laravel's Authenticate middleware:
- Option 1: Add to the middleware group
Openapp/Http/Kernel.php, and insert your custom middleware into theweborapigroup after the default authentication middleware:protected $middlewareGroups = [ 'web' => [ // ... other default middleware \App\Http\Middleware\Authenticate::class, \Vendor\MyCustom\Middleware\aMdl::class, // Place here ], ]; - Option 2: Chain middleware on routes
If attaching middleware directly to routes, explicitly listauthfirst to enforce order:Route::get('/your-endpoint', [aController::class, 'yourMethod']) ->middleware(['auth', 'your-custom-middleware-alias']);
2. Stop Trying to Access Auth in Controller Constructors
If you’re running user-dependent logic inside the controller’s __construct() (not just attaching middleware), that’s a dead end—constructors run before any middleware executes. Instead:
- Move the logic into your custom middleware (which will now run post-authentication)
- Or place the logic directly in your controller methods, which execute after all middleware processing is done.
3. Verify Service Provider Registration Order
Make sure your custom vendor package’s service provider is registered after Laravel’s core providers. In config/app.php, add your provider to the end of the providers array:
'providers' => [ // ... Laravel's core providers Vendor\MyCustom\Providers\YourServiceProvider::class, ],
This ensures Laravel’s authentication services are fully initialized before your middleware tries to use them.
4. Double-Check Middleware Alias Mapping
If you’re using an alias to call your middleware (e.g., $this->middleware('custom-mdl')), confirm it’s correctly mapped in Kernel.php:
protected $routeMiddleware = [ // ... other aliases 'custom-mdl' => \Vendor\MyCustom\Middleware\aMdl::class, ];
Quick Sanity Check
If you’re using the api middleware group, verify your config/auth.php has the correct default guard set for API routes—mismatched guards can sometimes cause unexpected null returns, though this is less likely if auth()->user() works elsewhere in your app.
内容的提问来源于stack exchange,提问作者Dr.Dre

