You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel Auth模型关系配置:如何实现网站后台用户权限关联查询

Laravel模型关联配置与管理员权限逻辑实现

嗨,我来帮你梳理下Laravel里这些模型的关联配置,还有你提到的管理员判定逻辑~

首先,先给四张表创建对应的Eloquent模型(如果还没创建的话):

  • php artisan make:model Authority
  • php artisan make:model Role
  • php artisan make:model User(默认项目里已经有这个模型,我们只需要修改它)

接下来逐个配置模型间的关联关系:

1. Authority模型(权限模型)

权限和角色是多对多关系:一个权限可以属于多个角色,一个角色可以拥有多个权限,通过role_authorities中间表关联:

// app/Models/Authority.php
namespace App\Models;

use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsToMany;

class Authority extends Model
{
    protected $fillable = ['name'];

    // 关联所属角色
    public function roles(): BelongsToMany
    {
        return $this->belongsToMany(Role::class, 'role_authorities', 'authority_id', 'role_id');
    }
}

2. Role模型(角色模型)

角色需要同时关联权限和用户,都是多对多关系:

// app/Models/Role.php
namespace App\Models;

use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsToMany;

class Role extends Model
{
    protected $fillable = ['name'];

    // 关联拥有的权限
    public function authorities(): BelongsToMany
    {
        return $this->belongsToMany(Authority::class, 'role_authorities', 'role_id', 'authority_id');
    }

    // 关联所属用户
    public function users(): BelongsToMany
    {
        return $this->belongsToMany(User::class, 'user_roles', 'role_id', 'user_id');
    }
}

3. User模型(用户模型)

用户和角色是多对多关系,我们在这里封装管理员判定和权限获取的快捷方法:

// app/Models/User.php
namespace App\Models;

use Illuminate\Foundation\Auth\User as Authenticatable;
use Illuminate\Database\Eloquent\Relations\BelongsToMany;

class User extends Authenticatable
{
    protected $fillable = ['name', 'email', 'password', 'mission'];

    // 关联拥有的角色,同时预加载权限避免N+1查询
    public function roles(): BelongsToMany
    {
        return $this->belongsToMany(Role::class, 'user_roles', 'user_id', 'role_id')
            ->with('authorities');
    }

    // 判断当前用户是否为管理员
    public function isAdmin(): bool
    {
        return $this->mission == 1;
    }

    // 获取用户所有权限(自动去重)
    public function getAllAuthorities()
    {
        return $this->roles->flatMap(function ($role) {
            return $role->authorities;
        })->unique('id');
    }
}

登录时获取角色与权限的逻辑

当用户登录后,你可以在登录控制器的authenticated方法里处理数据:

// app/Http/Controllers/Auth/LoginController.php
protected function authenticated(Request $request, $user)
{
    // 判定是否为管理员
    if ($user->isAdmin()) {
        // 获取带权限的角色列表
        $rolesWithAuthorities = $user->roles;
        // 获取所有权限集合
        $allAuthorities = $user->getAllAuthorities();

        // 可以把数据存入session,方便后台页面调用
        session([
            'admin_roles' => $rolesWithAuthorities,
            'admin_authorities' => $allAuthorities
        ]);
    }
}

小提示

  • 确保数据表字段和模型的$fillable对应,避免批量赋值异常
  • 预加载authorities能有效减少数据库查询次数,提升性能
  • 如果后续需要更复杂的权限控制,可以结合Laravel的Gate功能,不过当前配置已经能满足你的基础需求

内容的提问来源于stack exchange,提问作者coder2

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:59:39