我尝试在 cakePHP v.2.7 中找到一种良好而干净的方法来处理管理面板编辑用户".

I try to find a good and clean way to deal with an admin panel "edit user" in cakePHP v.2.7.

需要明确的是:我希望能够在覆盖或不覆盖用户密码的情况下编辑我的用户,但是 cakePHP 验证器工具不允许我做我想做的事...

To be clear : I want to be able to edit my user with or without overwriting their password, but the cakePHP validator tool don't let me do what I want...

我已经看过CakePHP:在不更改密码的情况下编辑用户 和 使用 CakePHP 更新用户电子邮件和密码 但似乎真的脏:

I've already take a look at CakePHP: Edit Users without changing password and Updating user email and password with CakePHP but it seem really dirty :

  • 第一个不应用更新规则
  • 第二个显示哈希值(只是没有... u_u")


There is no other way to do it ? (with as few line as possible)




// add in your view `app/View/Users/edit.ctp`
// a 'fake' field you'll only use on the controller
echo $this->Form->input('new_password');


// add in your controller `app/Model/User.php@edit()`
// if we have a new password, create key `password` in data
if(!empty($new_password = $this->request->data['User']['new_password']))
  $this->request->data['User']['password'] = $new_password;
else // else, we remove the rules on password



Ok, I finally get what I want, here is my code :

在您的 app/View/Users/edit.ctp 上,您将一个字段添加到表单中(自定义字段,不要将其添加到您的数据库中)

On your app/View/Users/edit.ctp you add a field to your form (a custom one, don't add it to your DB)

// app/View/Users/edit.ctp
echo $this->Form->create('User');
// your other fields
// a 'fake' field you'll only use on the controller
echo $this->Form->input('new_password');

不要改变你的 app/Model/User.php ;这是我的:

Don't change your app/Model/User.php ; here is mine :

// app/Model/User.php
App::uses('AuthComponent', 'Controller/Component');

class User extends AppModel {
  public $validate = array(
    // [...] other rules
    'password' => array(
        'rule' => array('minLength', 8),
        'message' => 'Too short...',
        'rule' => 'notBlank',
        'required' => true,
        'allowEmpty' => false,
        'message' => 'A password is required',

  public function beforeSave($options = array()) {
    if (!empty($pwd = $this->data[$this->alias]['password']))
      $this->data[$this->alias]['password'] = AuthComponent::password($pwd);

    return true;

在你的 app/Controller/UsersController.php 上你使用这个:

And on your app/Controller/UsersController.php you use this :

public function edit($id = null) {
  $this->User->id = $id;

  if (!$this->User->exists())
    throw new NotFoundException(__('Invalid user'));

  if ($this->request->is('post') || $this->request->is('put')) {
      // IMPORTANT >>>>>>>>>>>
      // if we have a new password, create key `password` in data
    if(!empty($new_password = $this->request->data['User']['new_password']))
      $this->request->data['User']['password'] = $new_password;
    else // else, we remove the rules on password
      // <<<<<<<<<<<<<<<<<<<<<

      // then we try to save
    if ($this->User->save($this->request->data)) {
      $this->Flash->success(__('The user has been updated'));
      $this->redirect(array('action' => 'index'));
      $this->Flash->warning(__('The user could not be updated.'));
  else {
    $this->request->data = $this->User->read(null, $id);

通过这 4 行重要代码,您现在可以根据需要设置新密码或禁用密码验证.

With the 4 important lines, you are now able to set a new password if needed or disable the validation on the password.


