Problem
Auth-specific behavior currently sits on the generic Model class (e.g. getAuthKeyName()). Model should stay generic. Only models that authenticate need auth methods and attributes.
The Auth facade also documents User, which is not a framework type. Auth already resolves the model configured per actor in config/auth.php, so locking the type to User is wrong.
Proposal
- Add an
Authable base class that extends Model and owns everything auth needs.
- Remove auth methods from
Model (starting with getAuthKeyName()).
- Put auth-related helpers on
Authable instead of reading raw attributes through Auth, including things like:
- auth key name (
getAuthKeyName())
- auth identifier / primary key
- password hash access
- remember token get/set
- two-factor secret / recovery codes access
- persist (
save()) where Auth needs it
- Type Auth (
Auth facade + Authenticate) against Authable, not User or an untyped $user.
- Application auth models (
User, later Admin, etc.) extend Authable instead of Model directly.
Multi-actor auth via config/auth.php stays the same. Each actor still points at its own model. Those models just extend Authable.
Example
// before
class User extends Model { ... }
// after
class User extends Authable { ... }
Problem
Auth-specific behavior currently sits on the generic
Modelclass (e.g.getAuthKeyName()).Modelshould stay generic. Only models that authenticate need auth methods and attributes.The Auth facade also documents
User, which is not a framework type. Auth already resolves the model configured per actor inconfig/auth.php, so locking the type toUseris wrong.Proposal
Authablebase class that extendsModeland owns everything auth needs.Model(starting withgetAuthKeyName()).Authableinstead of reading raw attributes through Auth, including things like:getAuthKeyName())save()) where Auth needs itAuthfacade +Authenticate) againstAuthable, notUseror an untyped$user.User, laterAdmin, etc.) extendAuthableinstead ofModeldirectly.Multi-actor auth via
config/auth.phpstays the same. Each actor still points at its own model. Those models just extendAuthable.Example