You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel:实现输入框密码与数据库密码校验及页面跳转需求

How to Fix Password Validation & Redirect Logic in Laravel

Hey there! Let's walk through fixing your code to get that password check working correctly. I notice a few small issues in both your Controller and view that are keeping things from working as expected.

Issues in Your Current Controller Code

  • You're injecting a check $check parameter but trying to use $request later—this will throw an error because $request isn't defined.
  • Site::return($request->all()); isn't valid Laravel syntax. There's no such method on a model (assuming Site is a model), and you need to handle the "invalid password" case properly.
  • If your passwords are stored as hashes (which they should be, per Laravel's best practices), comparing the raw input directly to the database value won't work—you need to use Laravel's Hash facade to verify the hash.
  • Using Input::get() is outdated; it's better to use the request instance's input() method.

Issues in Your View

  • The form is missing a submit button, so users can't send the password input.
  • You haven't added a POST method or CSRF token, which is required for Laravel to accept the form submission safely.

Fixed Controller Code

First, make sure you import the necessary classes at the top of your Controller:

use Illuminate\Http\Request;
use Illuminate\Support\Facades\Hash;
use App\Models\User; // Adjust the namespace if your User model is elsewhere

Then update the check method:

public function check(Request $request)
{
    // Optional but recommended: Validate the input first
    $request->validate([
        'password' => 'required|string',
    ]);

    // If you're checking against a specific user (e.g., by email), adjust this line
    // Example: $user = User::where('email', $request->email)->first();
    $user = User::first(); 

    // Verify the password hash against the stored value
    if ($user && Hash::check($request->input('password'), $user->password)) {
        return redirect()->route('site.create');
    }

    // If password is invalid, do nothing (matches your requirement)
    // Optional: Uncomment below to redirect back with an error message
    // return back()->withErrors(['password' => 'Invalid password provided']);
    return back();
}

Fixed View Code

Add the full form structure with CSRF token and submit button:

<form method="POST" action="{{ route('check.password') }}"> <!-- Replace with your actual route name -->
    @csrf
    <div class="form-group row">
        <label for="password" class="col-md-4 col-form-label text-md-right">{{ __('please type in your password') }}</label>
        <div class="col-md-6">
            <input id="password" type="password" class="form-control" name="password" required>
        </div>
    </div>

    <div class="form-group row mb-0">
        <div class="col-md-8 offset-md-4">
            <button type="submit" class="btn btn-primary">
                {{ __('Submit') }}
            </button>
        </div>
    </div>
</form>

Key Notes

  • Hash Best Practices: Always store passwords as hashes (use Hash::make() when creating users) and verify with Hash::check()—never compare raw passwords directly.
  • Route Setup: Make sure you have a route pointing to your check method in web.php:
    Route::post('/check-password', [YourController::class, 'check'])->name('check.password');
    
  • Error Feedback: If you want to show users an error when the password is wrong, uncomment the error redirect line in the Controller and add this to your view to display the message:
    @error('password')
        <span class="invalid-feedback" role="alert">
            <strong>{{ $message }}</strong>
        </span>
    @enderror
    

内容的提问来源于stack exchange,提问作者Devi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:41:18