What are we doing?
Laravel is a tool used to build websites with PHP. It keeps user names and passwords in a database. A database stores data in tables, like spreadsheet pages. Users live in a table, usually called users.
Laravel does not store the real password. It stores a scrambled version called a hash. So you cannot just type a new password into the table. You must type a hash.
Warning: Export a backup of your database first. Use the Export tab in phpMyAdmin. A wrong edit can lock everyone out.
Method 1: Use Tinker (SSH)
Tinker is a Laravel helper where you type small commands. You need SSH access. SSH lets you type commands on the server.
- Connect with SSH and go to your Laravel folder.
- Start Tinker.
php artisan tinker
- Find the user and set a new password. Change the email and password to yours.
$user = App\Models\User::where('email', 'admin@example.com')->first();
$user->password = Hash::make('NewStrongPassword');
$user->save();
This finds the user, scrambles the new password and saves it.
Method 2: Use phpMyAdmin
- Create a hash. In Tinker, run
echo Hash::make('NewStrongPassword');and copy the result. It starts with$2y$. - Open phpMyAdmin in your control panel.
- Click your database, then the
userstable. - Click Browse and find the admin row.
- Click Edit on that row.
- Paste the hash into the
passwordbox. - Click Go to save.
Log in
Open your login page. Use the email and the new password. Change the password again from inside the admin area when you can.
Some admin packages use another table or model name. Check your database to see what the table is called.
Quick recap
- Laravel stores a hash, not the plain password.
- Tinker is the easiest way to set a new one.
- Or paste a bcrypt hash into the
userstable in phpMyAdmin. - Back up the database first.