Laravel项目中无法编辑或删除帖子问题求助
Hey there! Let's figure out why you're hitting that "you can't edit post..." error when trying to modify or delete posts in Laravel. Since you mentioned using the Auth system's ID for permission control, here are the key areas to check and fix:
1. 检查控制器中的权限验证逻辑
First up, double-check your update and destroy controller methods—this is where permission checks usually go wrong. Make sure you're correctly comparing the logged-in user's ID to the post's user_id field.
Here's a correct example of how this should look:
public function edit(Ad $ad) { // Verify the current user owns the post if(Auth::id() !== $ad->user_id) { return redirect()->back()->with('error', "you can't edit post ..."); } return view('ads.edit', compact('ad')); } public function update(Request $request, Ad $ad) { if(Auth::id() !== $ad->user_id) { return redirect()->back()->with('error', "you can't edit post ..."); } // Proceed with update logic $ad->update($request->validated()); return redirect()->route('ads.index')->with('success', 'Post updated successfully'); } public function destroy(Ad $ad) { if(Auth::id() !== $ad->user_id) { return redirect()->back()->with('error', "you can't edit post ..."); } $ad->delete(); return redirect()->route('ads.index')->with('success', 'Post deleted successfully'); }
Watch out for these common mistakes:
- Missing
user_idfield: Ensure your post model (likeAd) has auser_idcolumn, and that you're saving the logged-in user's ID when creating the post. - Incorrect comparison: Don't mix up the order of
Auth::id()and$ad->user_id, or use a single equals sign (=) instead of double (==) or triple (===) for comparison.
2. Use Laravel Policies for Cleaner Permission Control
If your app is growing, using Laravel's built-in Policies will make permission management more organized and maintainable. Here's how to set it up:
- Generate a policy for your post model:
php artisan make:policy AdPolicy --model=Ad - Define the
updateanddeleterules inapp/Policies/AdPolicy.php:public function update(User $user, Ad $ad) { return $user->id === $ad->user_id; } public function delete(User $user, Ad $ad) { return $this->update($user, $ad); // Reuse the update permission logic } - Register the policy in
app/Providers/AuthServiceProvider.php:protected $policies = [ Ad::class => AdPolicy::class, ]; - Then, in your controller, use the
authorizemethod to handle permissions automatically:public function edit(Ad $ad) { $this->authorize('update', $ad); // Throws a 403 error if permission is denied return view('ads.edit', compact('ad')); }
3. Fix View Logic for Edit/Delete Buttons
While this won't fix the permission error itself, it improves user experience by only showing edit/delete buttons to the post owner:
@foreach($ads as $ad) <div class="post-card"> <h3>{{ $ad->title }}</h3> <p>{{ $ad->content }}</p> <!-- Only show buttons if user owns the post --> @if(Auth::check() && Auth::id() === $ad->user_id) <a href="{{ route('ads.edit', $ad) }}" class="btn btn-primary">Edit</a> <form action="{{ route('ads.destroy', $ad) }}" method="POST" style="display: inline;"> @csrf @method('DELETE') <button type="submit" class="btn btn-danger">Delete</button> </form> @endif </div> @endforeach
4. Verify Implicit Model Binding
If you're using implicit model binding, make sure your route parameter name matches the controller variable name. For example:
- Route definition:
Route::get('/ads/{ad}/edit', [AdController::class, 'edit'])->name('ads.edit'); - Controller method:
public function edit(Ad $ad) { ... }
Mismatched names will cause Laravel to fetch the wrong post (or none at all), leading to permission errors.
内容的提问来源于stack exchange,提问作者Obka

