基于Laravel Fortify实现多用户模型与子域名配置求助
Laravel 子域名区分多认证(用户/管理员独立模型)实现指南
你提到的修改auth.php、Fortify配置、守卫和管道是完全正确的核心路径,这正是Laravel实现多模型+子域名区分认证的标准方案。下面是一步步的具体实现指南:
一、准备管理员模型与数据表
- 生成Admin模型和对应的迁移文件:
php artisan make:model Admin -m - 打开生成的迁移文件,添加管理员所需字段(比如
name、email、password,和User模型字段保持一致即可),执行迁移:php artisan migrate - 给
App\Models\Admin模型添加必要的trait,确保符合Laravel认证规范:<?php namespace App\Models; use Illuminate\Foundation\Auth\User as Authenticatable; use Illuminate\Notifications\Notifiable; use Laravel\Fortify\TwoFactorAuthenticatable; use Laravel\Jetstream\HasProfilePhoto; use Laravel\Sanctum\HasApiTokens; class Admin extends Authenticatable { use HasApiTokens, HasProfilePhoto, Notifiable, TwoFactorAuthenticatable; protected $fillable = [ 'name', 'email', 'password', ]; protected $hidden = [ 'password', 'remember_token', 'two_factor_recovery_codes', 'two_factor_secret', ]; protected $casts = [ 'email_verified_at' => 'datetime', ]; }
二、配置认证守卫与提供者
打开config/auth.php,添加管理员专属的守卫和数据提供者:
- 在
guards数组中新增admin守卫:'guards' => [ 'web' => [ 'driver' => 'session', 'provider' => 'users', ], 'admin' => [ 'driver' => 'session', 'provider' => 'admins', ], ], - 在
providers数组中新增admins提供者:'providers' => [ 'users' => [ 'driver' => 'eloquent', 'model' => App\Models\User::class, ], 'admins' => [ 'driver' => 'eloquent', 'model' => App\Models\Admin::class, ], ],
三、适配Fortify多守卫认证
打开config/fortify.php,调整基础配置并给子域名路由指定守卫:
- 因为用Inertia自定义前端页面,先关闭Fortify默认视图:
'views' => false, - 在路由文件(比如
routes/web.php)中,给子域名分组绑定Fortify认证逻辑:// 普通用户路由(example.com) Route::domain('example.com')->group(function () { Fortify::loginView(function () { return Inertia::render('User/Login'); }); // 其他用户认证路由(注册、密码重置等)按需添加 })->middleware(['web', 'guest:web']); // 管理员路由(admin.example.com) Route::domain('admin.example.com')->group(function () { Fortify::loginView(function () { return Inertia::render('Admin/Login'); }); // 其他管理员认证路由按需添加 })->middleware(['web', 'guest:admin']); - 自定义登录跳转逻辑:创建
app/Http/Responses/AdminLoginResponse.php,让管理员登录后跳转到后台:
然后在<?php namespace App\Http\Responses; use Laravel\Fortify\Contracts\LoginResponse as LoginResponseContract; class AdminLoginResponse implements LoginResponseContract { public function toResponse($request) { return redirect()->intended('https://admin.example.com/dashboard'); } }App\Providers\FortifyServiceProvider中绑定这个响应类:use App\Http\Responses\AdminLoginResponse; use Laravel\Fortify\Contracts\LoginResponse; public function register() { $this->app->bind(LoginResponse::class, function ($app) { if ($app->request->getHost() === 'admin.example.com') { return new AdminLoginResponse(); } return $app->make(\Laravel\Fortify\Http\Responses\LoginResponse::class); }); }
四、路由与中间件约束
分别给普通用户和管理员配置路由分组,并指定对应守卫的认证中间件:
// 普通用户授权路由 Route::domain('example.com')->group(function () { Route::get('/', function () { return Inertia::render('User/Home'); })->middleware(['auth:web']); // 其他用户专属路由 }); // 管理员授权路由 Route::domain('admin.example.com')->group(function () { Route::get('/dashboard', function () { return Inertia::render('Admin/Dashboard'); })->middleware(['auth:admin']); // 其他管理员专属路由 });
这里的auth:admin中间件会强制验证当前登录的是Admin模型实例,auth:web则验证User模型。
五、本地开发测试注意事项
- 修改本地hosts文件,添加:
确保子域名能正常访问。127.0.0.1 example.com 127.0.0.1 admin.example.com - 若需要跨子域名共享session(比如用户和管理员不能同时登录的场景),修改
config/session.php中的domain为.example.com。
内容的提问来源于stack exchange,提问作者BaraHinozuka
相关产品推荐
相关产品推荐

