Laravel:实现输入框密码与数据库密码校验及页面跳转需求
How to Fix Password Validation & Redirect Logic in Laravel
Hey there! Let's walk through fixing your code to get that password check working correctly. I notice a few small issues in both your Controller and view that are keeping things from working as expected.
Issues in Your Current Controller Code
- You're injecting a
check $checkparameter but trying to use$requestlater—this will throw an error because$requestisn't defined. Site::return($request->all());isn't valid Laravel syntax. There's no such method on a model (assumingSiteis a model), and you need to handle the "invalid password" case properly.- If your passwords are stored as hashes (which they should be, per Laravel's best practices), comparing the raw input directly to the database value won't work—you need to use Laravel's
Hashfacade to verify the hash. - Using
Input::get()is outdated; it's better to use the request instance'sinput()method.
Issues in Your View
- The form is missing a submit button, so users can't send the password input.
- You haven't added a
POSTmethod or CSRF token, which is required for Laravel to accept the form submission safely.
Fixed Controller Code
First, make sure you import the necessary classes at the top of your Controller:
use Illuminate\Http\Request; use Illuminate\Support\Facades\Hash; use App\Models\User; // Adjust the namespace if your User model is elsewhere
Then update the check method:
public function check(Request $request) { // Optional but recommended: Validate the input first $request->validate([ 'password' => 'required|string', ]); // If you're checking against a specific user (e.g., by email), adjust this line // Example: $user = User::where('email', $request->email)->first(); $user = User::first(); // Verify the password hash against the stored value if ($user && Hash::check($request->input('password'), $user->password)) { return redirect()->route('site.create'); } // If password is invalid, do nothing (matches your requirement) // Optional: Uncomment below to redirect back with an error message // return back()->withErrors(['password' => 'Invalid password provided']); return back(); }
Fixed View Code
Add the full form structure with CSRF token and submit button:
<form method="POST" action="{{ route('check.password') }}"> <!-- Replace with your actual route name --> @csrf <div class="form-group row"> <label for="password" class="col-md-4 col-form-label text-md-right">{{ __('please type in your password') }}</label> <div class="col-md-6"> <input id="password" type="password" class="form-control" name="password" required> </div> </div> <div class="form-group row mb-0"> <div class="col-md-8 offset-md-4"> <button type="submit" class="btn btn-primary"> {{ __('Submit') }} </button> </div> </div> </form>
Key Notes
- Hash Best Practices: Always store passwords as hashes (use
Hash::make()when creating users) and verify withHash::check()—never compare raw passwords directly. - Route Setup: Make sure you have a route pointing to your
checkmethod inweb.php:Route::post('/check-password', [YourController::class, 'check'])->name('check.password'); - Error Feedback: If you want to show users an error when the password is wrong, uncomment the error redirect line in the Controller and add this to your view to display the message:
@error('password') <span class="invalid-feedback" role="alert"> <strong>{{ $message }}</strong> </span> @enderror
内容的提问来源于stack exchange,提问作者Devi
相关产品推荐
相关产品推荐

