Bird
Raised Fist0
Laravelframework~5 mins

Security best practices in Laravel

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction

Security best practices help keep your Laravel app safe from hackers and data leaks. They protect users and your work.

When building a login system to protect user accounts
When handling user input to avoid harmful data
When storing sensitive data like passwords or payment info
When creating APIs that need to be secure
When deploying your app to the internet
Syntax
Laravel
1. Use Laravel's built-in CSRF protection with @csrf in forms.
2. Validate all user input using Request validation.
3. Hash passwords using bcrypt via Hash::make().
4. Use Laravel's Eloquent ORM to prevent SQL injection.
5. Escape output in Blade templates with {{ }}.
6. Use HTTPS and secure cookies.
7. Limit login attempts with throttle middleware.

Laravel helps with many security tasks automatically.

Always keep Laravel and its packages updated for security fixes.

Examples
This form uses @csrf to protect against cross-site request forgery attacks.
Laravel
<form method="POST" action="/login">
  @csrf
  <input type="email" name="email" required>
  <input type="password" name="password" required>
  <button type="submit">Login</button>
</form>
Hash::make() safely hashes passwords before saving them.
Laravel
use IlluminateSupportFacadesHash;

$password = 'secret123';
$hashed = Hash::make($password);
Validating input ensures only safe and expected data is saved.
Laravel
public function store(Request $request) {
  $validated = $request->validate([
    'name' => 'required|string|max:255',
    'email' => 'required|email|unique:users',
  ]);
  User::create($validated);
}
Blade's {{ }} escapes output to prevent cross-site scripting (XSS).
Laravel
<p>Hello, {{ $user->name }}!</p>
Sample Program

This example shows a simple user registration with input validation, CSRF protection, and password hashing.

Laravel
<?php

namespace AppHttpControllers;

use IlluminateHttpRequest;
use IlluminateSupportFacadesHash;
use AppModelsUser;

class RegisterController extends Controller
{
    public function showForm()
    {
        return view('register');
    }

    public function register(Request $request)
    {
        $validated = $request->validate([
            'name' => 'required|string|max:255',
            'email' => 'required|email|unique:users',
            'password' => 'required|string|min:8|confirmed',
        ]);

        $user = User::create([
            'name' => $validated['name'],
            'email' => $validated['email'],
            'password' => Hash::make($validated['password']),
        ]);

        return redirect('/welcome')->with('message', 'Registration successful!');
    }
}

// Blade view: resources/views/register.blade.php
// <form method="POST" action="/register">
//   @csrf
//   <input type="text" name="name" required>
//   <input type="email" name="email" required>
//   <input type="password" name="password" required>
//   <input type="password" name="password_confirmation" required>
//   <button type="submit">Register</button>
// </form>
OutputSuccess
Important Notes

Never store plain passwords; always hash them.

Use Laravel's validation to avoid bad data and attacks.

Keep your app updated to get latest security patches.

Summary

Use Laravel's built-in tools for security like CSRF tokens and validation.

Always hash passwords before saving.

Validate and escape all user input and output.

Practice

(1/5)
1. Which Laravel feature helps protect your application from Cross-Site Request Forgery (CSRF) attacks?
easy
A. Storing passwords in plain text
B. Using raw SQL queries without bindings
C. CSRF tokens automatically added to forms
D. Disabling middleware in routes

Solution

  1. Step 1: Understand CSRF attacks

    CSRF attacks trick users into submitting unwanted requests. Laravel uses tokens to prevent this.
  2. Step 2: Identify Laravel's protection method

    Laravel automatically adds CSRF tokens to forms and verifies them on submission.
  3. Final Answer:

    CSRF tokens automatically added to forms -> Option C
  4. Quick Check:

    CSRF protection = CSRF tokens [OK]
Hint: CSRF protection means using tokens in forms [OK]
Common Mistakes:
  • Thinking raw SQL protects against CSRF
  • Disabling middleware removes security
  • Storing passwords in plain text is unsafe
2. Which of the following is the correct way to hash a password before saving it in Laravel?
easy
A. $hashed = Hash::make($password);
B. $hashed = bcrypt($password);
C. $hashed = md5($password);
D. $hashed = base64_encode($password);

Solution

  1. Step 1: Identify Laravel's recommended password hashing

    Laravel provides the Hash facade's make method for secure password hashing.
  2. Step 2: Compare options

    $hashed = Hash::make($password); is the recommended and most flexible method. bcrypt() helper is valid but less flexible. md5 and base64_encode are insecure.
  3. Final Answer:

    $hashed = Hash::make($password); -> Option A
  4. Quick Check:

    Password hashing = Hash::make() [OK]
Hint: Use Hash::make() for password hashing in Laravel [OK]
Common Mistakes:
  • Using insecure md5 or base64_encode
  • Confusing Hash::make without import
  • Saving passwords without hashing
3. Consider this Laravel route definition:
Route::middleware(['auth'])->group(function () {
    Route::get('/dashboard', function () {
        return 'Welcome to your dashboard';
    });
});
What will happen if a guest (not logged in) tries to access /dashboard?
medium
A. They will see the dashboard message
B. They will be redirected to the login page
C. They will get a 404 Not Found error
D. They will see a blank page

Solution

  1. Step 1: Understand the 'auth' middleware

    The 'auth' middleware restricts access to authenticated users only.
  2. Step 2: Behavior for guests

    If a guest tries to access a route with 'auth' middleware, Laravel redirects them to the login page.
  3. Final Answer:

    They will be redirected to the login page -> Option B
  4. Quick Check:

    Auth middleware redirects guests [OK]
Hint: Auth middleware redirects guests to login [OK]
Common Mistakes:
  • Assuming guests see the dashboard
  • Expecting 404 error instead of redirect
  • Thinking middleware shows blank page
4. This Laravel controller method is intended to validate user input securely:
public function store(Request $request) {
    $data = $request->validate([
        'email' => 'required|email',
        'password' => 'required|min:8'
    ]);
    User::create($data);
}
What is the main security issue here?
medium
A. Passwords are not hashed before saving
B. Email validation rule is incorrect
C. Validation rules are missing CSRF token check
D. User::create() should be User::update()

Solution

  1. Step 1: Check validation rules

    The validation correctly checks email and password format.
  2. Step 2: Check password handling

    The password is saved directly without hashing, which is insecure.
  3. Final Answer:

    Passwords are not hashed before saving -> Option A
  4. Quick Check:

    Passwords must be hashed before saving [OK]
Hint: Always hash passwords before saving to database [OK]
Common Mistakes:
  • Assuming validation hashes passwords
  • Confusing CSRF with validation rules
  • Thinking create() vs update() affects security here
5. You want to protect an API route in Laravel so only authenticated users with the role 'admin' can access it. Which is the best approach?
hard
A. Use 'auth' middleware and check role inside the controller method
B. Use 'guest' middleware and check role in middleware
C. No middleware needed; check role in the route definition
D. Use 'auth' middleware and create a custom middleware to check 'admin' role

Solution

  1. Step 1: Understand middleware roles

    'auth' middleware ensures user is logged in; role checks require custom logic.
  2. Step 2: Best practice for role checks

    Create a custom middleware to check if the authenticated user has 'admin' role, then apply both middlewares.
  3. Final Answer:

    Use 'auth' middleware and create a custom middleware to check 'admin' role -> Option D
  4. Quick Check:

    Combine auth + custom role middleware [OK]
Hint: Combine auth middleware with custom role middleware [OK]
Common Mistakes:
  • Using 'guest' middleware for authenticated routes
  • Checking roles only inside controller
  • Skipping middleware for role checks