【问题标题】:Laravel Policy (Too few arguments to function App\Policy)Laravel 策略(App\Policy 函数的参数太少)
【发布时间】:2019-03-05 02:55:37
【问题描述】:

我正在尝试为用户设置我的策略。但是我不断收到以下错误:

函数 App\Policies\UserPolicy::update() 的参数太少,在第 481 行的 /vendor/laravel/framework/src/Illuminate/Auth/Access/Gate.php 中传递了 1 个,而预期的正好是 2 个(查看: /resources/views/users/index.blade.php)

ErrorException /app/Policies/UserPolicy.php 20

在 UserPolicy@update 函数中

当我以 super_admin 身份登录时,它工作正常,但每当我以不同角色的用户身份登录时,它都会引发此错误。

下面是我目前的实现:

用户策略

class UserPolicy
{
    use HandlesAuthorization;

    public function update(User $user, User $userEdit)  {
        if ($user->id == $userEdit->id) {
            return true;
        }
        return $user->can('update_user');
    }

    public function before($user, $ability) {
        if ($user->hasRole('super_admin')) {
            return true;
        }
    }
}

用户控制器

class UsersController extends Controller {

    public function __construct() {
        $this->middleware('auth');
    }

    public function edit(User $user) {
        $this->authorize('update', $user);
        return view('users.edit', [
            'user' => User::with('roles', 'level')->find($user->id),
            'surveys' => \App\Survey::all(),
        ]);
    }

    public function update(UserRequest $request, User $user) {
        $this->authorize('update', $user);
        $request->save();
        session()->flash('success', 'User successfully updated');

        // means user is editing his own profile
        if (auth()->id() == $user->id) {
            return redirect('/dashboard');
        } else {
            return redirect('/users');
        }
    }
}

用户请求

class UserRequest extends FormRequest {

    public function authorize() {
        return true;
    }

    public function rules() {
        switch ($this->method()) {
            case 'POST':
                return [
                    'name' => 'required|string',
                    'email' => 'required|string|email|max:255|unique:users',
                    'role'  => 'required|exists:roles,id',
                    'level' => 'required|string',
                ];
                break;

            case 'PATCH':
                return [
                    'name' => 'required|string|max:255',
                    'email' => 'required|string|email|max:255|unique:users,email,'.$this->user->id,
                    'role'  => 'sometimes|exists:roles,id',
                    'level' => 'sometimes|string',
                    'password' => 'nullable|sometimes|string|min:6|confirmed'
                ];
                break;

            default:
                break;
        }
    }

    public function save() {
        switch (request()->method()) {
            case 'POST':
                $this->createUser();
                break;

            case 'PATCH':
                $this->updateUser();
                break;

            default:
                break;
        }
    }

    protected function createUser() {
        // random generate password
        $password = str_random(8);

        $user = User::create([
            'name' => request('name'),
            'email' => request('email'),
            'level_id' => request('level'),
            'password' => Hash::make($password),
        ]);
        $user->assignRoleById(request('role'));

        Mail::to($user)->send(new WelcomeMail($user, $password));
    }

    protected function updateUser() {
        $user = User::findOrFail($this->user->id);
        $user->name = request('name');
        $user->email = request('email');

        if (request('password') != '') {
            $user->password = Hash::make(request('password'));
        }

        if (request('level') != '') {
            $user->level_id = request('level');
        }

        $user->update();

        if (request('role') != '') {
            $user->roles()->sync([request('role')]);
        }
    }
}

AuthServiceProvider

class AuthServiceProvider extends ServiceProvider
{
    /**
     * The policy mappings for the application.
     *
     * @var array
     */
    protected $policies = [
        \App\User::class => \App\Policies\UserPolicy::class,
    ];

    /**
     * Register any authentication / authorization services.
     *
     * @return void
     */
    public function boot()
    {
        $this->registerPolicies();
        foreach ($this->getPermissions() as $permission) {
            Gate::define($permission->name, function($user) use ($permission) {
                return $user->hasRole($permission->roles);
            });
        }
    }

    protected function getPermissions() {
        return Permission::with('roles')->get();
    }
}

【问题讨论】:

    标签: php laravel


    【解决方案1】:

    在我正在调用的视图文件中

    @can('update', App\User::class)
        <!-- html code --!>
    @endcan
    

    而不是

    @can('update', $user)
        <!-- html code --!>
    @endcan
    

    我没有将用户实例传递给导致错误的函数。

    【讨论】:

      【解决方案2】:

      UserRequest 中调用$user-&gt;update(); 时没有给出任何参数。 update() 函数需要 UserRequest 实例以及 User

      试试看:$user-&gt;update(request()-&gt;all(), $user)

      编辑: 我只是移动以下...

      $this->authorize('update', $user);
      $request->save();
      session()->flash('success', 'User successfully updated');
      
      // means user is editing his own profile
      if (auth()->id() == $user->id) {
          return redirect('/dashboard');
      } else {
          return redirect('/users');
      }
      

      ...到updateUser() 函数。

      【讨论】:

      • 或者你应该调用 $user->save() 而不是 update() 来将应用的更改持久化到 db。
      • 错误仍然存​​在。此错误在执行 UserController@index 时已经触发,它不仅在我运行 UserController@update 时发生
      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2022-08-17
      • 2021-02-21
      • 1970-01-01
      • 2021-05-14
      • 2020-07-30
      • 1970-01-01
      相关资源
      最近更新 更多