You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel项目中无法编辑或删除帖子问题求助

Laravel 帖子编辑/删除权限错误排查方案

Hey there! Let's figure out why you're hitting that "you can't edit post..." error when trying to modify or delete posts in Laravel. Since you mentioned using the Auth system's ID for permission control, here are the key areas to check and fix:

1. 检查控制器中的权限验证逻辑

First up, double-check your update and destroy controller methods—this is where permission checks usually go wrong. Make sure you're correctly comparing the logged-in user's ID to the post's user_id field.

Here's a correct example of how this should look:

public function edit(Ad $ad)
{
    // Verify the current user owns the post
    if(Auth::id() !== $ad->user_id) {
        return redirect()->back()->with('error', "you can't edit post ...");
    }
    return view('ads.edit', compact('ad'));
}

public function update(Request $request, Ad $ad)
{
    if(Auth::id() !== $ad->user_id) {
        return redirect()->back()->with('error', "you can't edit post ...");
    }
    // Proceed with update logic
    $ad->update($request->validated());
    return redirect()->route('ads.index')->with('success', 'Post updated successfully');
}

public function destroy(Ad $ad)
{
    if(Auth::id() !== $ad->user_id) {
        return redirect()->back()->with('error', "you can't edit post ...");
    }
    $ad->delete();
    return redirect()->route('ads.index')->with('success', 'Post deleted successfully');
}

Watch out for these common mistakes:

  • Missing user_id field: Ensure your post model (like Ad) has a user_id column, and that you're saving the logged-in user's ID when creating the post.
  • Incorrect comparison: Don't mix up the order of Auth::id() and $ad->user_id, or use a single equals sign (=) instead of double (==) or triple (===) for comparison.

2. Use Laravel Policies for Cleaner Permission Control

If your app is growing, using Laravel's built-in Policies will make permission management more organized and maintainable. Here's how to set it up:

  1. Generate a policy for your post model:
    php artisan make:policy AdPolicy --model=Ad
    
  2. Define the update and delete rules in app/Policies/AdPolicy.php:
    public function update(User $user, Ad $ad)
    {
        return $user->id === $ad->user_id;
    }
    
    public function delete(User $user, Ad $ad)
    {
        return $this->update($user, $ad); // Reuse the update permission logic
    }
    
  3. Register the policy in app/Providers/AuthServiceProvider.php:
    protected $policies = [
        Ad::class => AdPolicy::class,
    ];
    
  4. Then, in your controller, use the authorize method to handle permissions automatically:
    public function edit(Ad $ad)
    {
        $this->authorize('update', $ad); // Throws a 403 error if permission is denied
        return view('ads.edit', compact('ad'));
    }
    

3. Fix View Logic for Edit/Delete Buttons

While this won't fix the permission error itself, it improves user experience by only showing edit/delete buttons to the post owner:

@foreach($ads as $ad)
    <div class="post-card">
        <h3>{{ $ad->title }}</h3>
        <p>{{ $ad->content }}</p>
        <!-- Only show buttons if user owns the post -->
        @if(Auth::check() && Auth::id() === $ad->user_id)
            <a href="{{ route('ads.edit', $ad) }}" class="btn btn-primary">Edit</a>
            <form action="{{ route('ads.destroy', $ad) }}" method="POST" style="display: inline;">
                @csrf
                @method('DELETE')
                <button type="submit" class="btn btn-danger">Delete</button>
            </form>
        @endif
    </div>
@endforeach

4. Verify Implicit Model Binding

If you're using implicit model binding, make sure your route parameter name matches the controller variable name. For example:

  • Route definition:
    Route::get('/ads/{ad}/edit', [AdController::class, 'edit'])->name('ads.edit');
    
  • Controller method:
    public function edit(Ad $ad) { ... }
    

Mismatched names will cause Laravel to fetch the wrong post (or none at all), leading to permission errors.

内容的提问来源于stack exchange,提问作者Obka

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:59:54