Laravel:重置密码无需验证即可获得6位数字

Jav*_*ved 1 laravel laravel-5.5

我有简单的功能来重置我的密码。在我的函数中,对password值的最低要求是,1 digit但是当我尝试更新密码时它没有更新,当我6 digits输入密码时它工作正常。

我发现在vendor\laravel\framework\src\Illuminate\Auth\Passwords一个passwordBroker.php文件中有一个功能

 protected function validatePasswordWithDefaults(array $credentials)
{
    list($password, $confirm) = [
        $credentials['password'],
        $credentials['password_confirmation'],
    ];

    return $password === $confirm && mb_strlen($password) >= 6; // here it is
}
Run Code Online (Sandbox Code Playgroud)

并且它包含验证($password) >= 6我如何删除它,当我更改此文件时它正在工作。在我的.gitignore vendor文件夹中未实时更新。解决办法是什么 ?如何覆盖此验证?

供参考这里是我的resetpassword功能

public function resetPassword(ResetPasswordRequest $request, JWTAuth $JWTAuth)
{
    $validator = Validator::make($request->all(), User::resetPasswordRules());
    if ($validator->fails()) {
        return response()->json([
            'message'       => "422 Unprocessable Entity",
            'errors'        => $validator->messages(),
            'status_code'   => 422,
        ]);
    }


    $response = $this->broker()->reset(
        $this->credentials($request), function ($user, $password) {
            $this->reset($user, $password);
        }
    );

    if($response !== Password::PASSWORD_RESET) {
        return response()->json([
                'message'       => "Internal Server Error",
                'status_code'   => 500,
            ]);
    }
    $user = User::where('email', '=', $request->get('email'))->first();
    $user->UserDeviceData()->firstOrCreate([
        'device_id' => $request->device_id
    ]);

     return (new UserTransformer)->transform($user,[
        'request_type'  => 'reset_password',
        'token'         =>  $JWTAuth->fromUser($user)
    ]);
}
Run Code Online (Sandbox Code Playgroud)

the*_*len 5

这是您可以解决此问题的方法:

public function resetPassword(ResetPasswordRequest $request, JWTAuth $JWTAuth)
{
    ... // Validator check and json response

    $broker = $this->broker();

    // Replace default validation of the PasswordBroker
    $broker->validator(function (array $credentials) {
        return true; // Password match is already validated in PasswordBroker so just return true here
    });

    $response = $broker->reset(
        $this->credentials($request), function ($user, $password) {
        $this->reset($user, $password);
    });

    ...
}
Run Code Online (Sandbox Code Playgroud)

首先,您生成代理的一个实例,然后添加一个可调用函数,它将用于验证而不是validatePasswordWithDefaults. 在那里你只需要返回 true 因为 PasswordBroker 已经有一个 check $password === $confirm。