dragon_9000 2015-09-17 16:24
I am converting an internal API from HTML (back-end) processing to JSON (using Knockout.js) processing on the client-side to load a bunch of entities (vehicles, in my case).

The thing is our database stores sensitive information that cannot be revelead in the API since someone could simply reverse engineer the request and gather them.

Therefore I am trying to select specifically for every relationship eager-load the columns I wish to publish in the API, however I am having issues at loading a model relationship because it seems like Eloquent automatically loads every column of the parent model whenever a relationship model is eager loaded.

Sounds like a mindfuck, I am aware, so I'll try to be more comprehensive.

Our database stores many Contract, and each of them has assigned a Vehicle.

A Contract has assigned an User.

A Vehicle has assigned many Photo.

So here's the current code structure:

class Contract
    public function user()
        return $this->belongsTo('User');

    public function vehicle()
        return $this->belongsTo('Vehicle');

class Vehicle
    public function photos()
        return $this->hasMany('Photo', 'vehicle_id');

class Photo

Since I need to eager load every single relationship listed above and for each relationship a specific amount of columns, I need to do the following:


$query = Contract::join('vehicles as vehicle', 'vehicle.id', '=', 'contract.vehicle_id')->select([


$query = $query->with(['vehicle' => function ($query) {

$query = $query->with(['vehicle.photos' => function ($query) {
    ])->where('order', '<=', 0);

$query = $query->with(['user' => function ($query) {

$query = $query->with(['office' => function ($query) {


return $this->response->json([
    'error'           => false,
    'vehicles'        => $vehicles->getItems(),
    'pagination'      => [
        'currentPage' => (integer) $vehicles->getCurrentPage(),
        'lastPage'    => (integer) $vehicles->getLastPage(),
        'perPage'     => (integer) $vehicles->getPerPage(),
        'total'       => (integer) $vehicles->getTotal(),
        'from'        => (integer) $vehicles->getFrom(),
        'to'          => (integer) $vehicles->getTo(),
        'count'       => (integer) $vehicles->count()
    'banner'          => rand(0, 2),
    'filters'         => (count($input) > 4),
    'filtersHelpText' => generateSearchString($input)

The issue is: if I do not eager load vehicle.photos relationship, columns are loaded properly. Otherwise, every single column of Vehicle's model is loaded.

Here's some pictures so you can understand:

Picture when vehicle.photos isn't eager-loaded.

Picture when vehicle.photos is eager-loaded.

Note: some information have been removed from the pictures since they are sensitive information.

  donglanfu5831 2015-09-17 21:27

    You can set a hidden property on your models which is an array of column names you want to hide from being output.

    protected $hidden = ['password'];
