Laravel 中间件 return 用户信息为空

Laravel Middleware return user info as null

我创建了一个中间层来防止用户不插入或更新任何东西。我在 Laravel 5.6

<?php

namespace App\Http\Middleware;

use Closure;
use Illuminate\Support\Facades\Auth;
class LimitDemoUser
{
    /**
     * Handle an incoming request.
     *
     * @param  \Illuminate\Http\Request  $request
     * @param  \Closure  $next
     * @return mixed
     */
    public function handle($request, Closure $next)
    {
        $userId = Auth::id();
        if(request()->method() != "GET" && request()->method() != "HEAD" && $userId == 6) {
            abort(403);
        }
        return $next($request);
    }
}

我像这样将它注册到内核 (LimitDemoUser)

protected $middleware = [
    \Illuminate\Foundation\Http\Middleware\CheckForMaintenanceMode::class,
    \Illuminate\Foundation\Http\Middleware\ValidatePostSize::class,
    \App\Http\Middleware\TrimStrings::class,
    \Illuminate\Foundation\Http\Middleware\ConvertEmptyStringsToNull::class,
    \App\Http\Middleware\TrustProxies::class,
    \App\Http\Middleware\LimitDemoUser::class,

];

但是当我 dd(Auth::id());我得到的是空值而不是登录用户 ID

我在这里错过了什么?

我想我没有向 routemiddleware 添加任何东西

protected $routeMiddleware = [
    'auth' => \Illuminate\Auth\Middleware\Authenticate::class,
    'auth.basic' => \Illuminate\Auth\Middleware\AuthenticateWithBasicAuth::class,
    'bindings' => \Illuminate\Routing\Middleware\SubstituteBindings::class,
    'cache.headers' => \Illuminate\Http\Middleware\SetCacheHeaders::class,
    'can' => \Illuminate\Auth\Middleware\Authorize::class,
    'guest' => \App\Http\Middleware\RedirectIfAuthenticated::class,
    'throttle' => \Illuminate\Routing\Middleware\ThrottleRequests::class,

];

我的登录控制器在下面。也许它可以帮助

<?php

namespace App\Http\Controllers\Auth;

use App\Http\Controllers\Controller;
use Illuminate\Foundation\Auth\AuthenticatesUsers;

class LoginController extends Controller
{
    /*
    |--------------------------------------------------------------------------
    | Login Controller
    |--------------------------------------------------------------------------
    |
    | This controller handles authenticating users for the application and
    | redirecting them to your home screen. The controller uses a trait
    | to conveniently provide its functionality to your applications.
    |
    */

    use AuthenticatesUsers;

    /**
     * Where to redirect users after login.
     *
     * @var string
     */
    protected $redirectTo = '/login';

    /**
     * Create a new controller instance.
     *
     * @return void
     */
    public function __construct()
    {
        $this->middleware('guest')->except('logout');
    }

    public function logout()
    {
        $this->guard()->logout();

        return redirect()->route('login');
    }

}

您的 loginController 应该如下所示:

class LoginController extends Controller
{
    /**
     * Handle an authentication attempt.
     *
     * @return Response
     */
    public function authenticate()
    {
        if (Auth::attempt(['email' => $email, 'password' => $password])) {
            // Authentication passed...
            return redirect()->intended('dashboard');
        }
    }
}

当你想获取用户id时,你应该将用户class.

if (Auth::check())
{
    // The user is logged in...
    Auth::user()->id;
}
else
{
    echo "You are not logged in";
}

尝试将您的 web.php 更改为

Route::middleware(['limitdemouser'])->group(function () {
  Auth::routes();
});

你的 $routeMiddleware 是

protected $routeMiddleware = [
    'auth' => \Illuminate\Auth\Middleware\Authenticate::class,
    'auth.basic' => \Illuminate\Auth\Middleware\AuthenticateWithBasicAuth::class,
    'bindings' => \Illuminate\Routing\Middleware\SubstituteBindings::class,
    'cache.headers' => \Illuminate\Http\Middleware\SetCacheHeaders::class,
    'can' => \Illuminate\Auth\Middleware\Authorize::class,
    'guest' => \App\Http\Middleware\RedirectIfAuthenticated::class,
    'throttle' => \Illuminate\Routing\Middleware\ThrottleRequests::class,
    'limitdemouser' => \App\Http\Middleware\LimitDemoUser::class,
];

如果不行请告诉我

我在此页面中找到了解决方案。 https://laracasts.com/discuss/channels/laravel/current-user-in-middleware

OP 声明

i have added the following code in the global middleware and nou is het working 
\App\Http\Middleware\EncryptCookies::class, \Illuminate\Session\Middleware\StartSession::class,

它很脏,但它能用。我认为这不是最佳做法,但它解决了问题。既然我们发现了问题,那么有人可以从这里提出一个像样的解决方案吗?

\App\Http\Middleware\LimitDemoUser::class 添加到 web 中间件组数组的末尾。

protected $middlewareGroups = [
    'web' => [
        ...,
        \App\Http\Middleware\LimitDemoUser::class,
     ]
];