Bird
Raised Fist0
Laravelframework~20 mins

Security best practices in Laravel - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
Laravel Security Master
Get all challenges correct to earn this badge!
Test your skills under time pressure!
🧠 Conceptual
intermediate
1:30remaining
What is the primary purpose of Laravel's CSRF protection?

Laravel includes CSRF protection by default. What does this protect your application from?

APrevent attackers from submitting forms on behalf of authenticated users without their consent.
BEncrypt user passwords before saving them to the database.
CLimit the number of login attempts to prevent brute force attacks.
DStop SQL injection attacks by escaping database queries.
Attempts:
2 left
💡 Hint

Think about what happens if a malicious site tries to submit a form on your site without permission.

❓ component_behavior
intermediate
1:30remaining
What happens if you forget to validate user input in a Laravel controller?

Consider a Laravel controller method that processes user input but does not validate it. What is the most likely risk?

Laravel
public function store(Request $request) {
    $data = $request->all();
    User::create($data);
    return redirect('/users');
}
AThe application will run slower but remain secure.
BLaravel will automatically reject the request and show an error page.
CThe user input will be sanitized automatically by Laravel.
DThe application may save invalid or malicious data, leading to security issues like SQL injection or broken data.
Attempts:
2 left
💡 Hint

Think about what happens when you trust user input without checking it.

📝 Syntax
advanced
1:30remaining
Which code snippet correctly hashes a password before saving a new user in Laravel?

Choose the code that securely hashes the password before saving it to the database.

AUser::create(['name' => $name, 'email' => $email, 'password' => hash('sha256', $password)]);
BUser::create(['name' => $name, 'email' => $email, 'password' => $password]);
CUser::create(['name' => $name, 'email' => $email, 'password' => bcrypt($password)]);
DUser::create(['name' => $name, 'email' => $email, 'password' => md5($password)]);
Attempts:
2 left
💡 Hint

Laravel provides a helper function specifically for hashing passwords securely.

🔧 Debug
advanced
2:00remaining
Why does this Laravel middleware fail to block unauthenticated users?

Review the middleware code below. Why does it not redirect unauthenticated users to the login page?

Laravel
public function handle($request, Closure $next) {
    if (!Auth::check()) {
        return redirect('/login');
    }
    return $next($request);
}
AThe middleware does not return the result of $next($request), so the request continues without redirecting.
BAuth::check() always returns true, so the condition never triggers.
CThe redirect URL '/login' is incorrect and causes a 404 error.
DMiddleware must be registered in the kernel to work, so this code never runs.
Attempts:
2 left
💡 Hint

Look carefully at the last line inside the handle method.

❓ lifecycle
expert
2:00remaining
At which point in Laravel's request lifecycle is the encryption of cookies handled?

Identify when Laravel encrypts cookies during the request lifecycle.

AAfter the controller returns a response, just before sending it to the browser.
BDuring the EncryptCookies middleware, which runs before the request reaches the controller.
CWhen the cookies are accessed inside the controller method.
DCookies are never encrypted automatically by Laravel.
Attempts:
2 left
💡 Hint

Think about middleware order and what EncryptCookies does.

Practice

(1/5)
1. Which Laravel feature helps protect your application from Cross-Site Request Forgery (CSRF) attacks?
easy
A. Storing passwords in plain text
B. Using raw SQL queries without bindings
C. CSRF tokens automatically added to forms
D. Disabling middleware in routes

Solution

  1. Step 1: Understand CSRF attacks

    CSRF attacks trick users into submitting unwanted requests. Laravel uses tokens to prevent this.
  2. Step 2: Identify Laravel's protection method

    Laravel automatically adds CSRF tokens to forms and verifies them on submission.
  3. Final Answer:

    CSRF tokens automatically added to forms -> Option C
  4. Quick Check:

    CSRF protection = CSRF tokens [OK]
Hint: CSRF protection means using tokens in forms [OK]
Common Mistakes:
  • Thinking raw SQL protects against CSRF
  • Disabling middleware removes security
  • Storing passwords in plain text is unsafe
2. Which of the following is the correct way to hash a password before saving it in Laravel?
easy
A. $hashed = Hash::make($password);
B. $hashed = bcrypt($password);
C. $hashed = md5($password);
D. $hashed = base64_encode($password);

Solution

  1. Step 1: Identify Laravel's recommended password hashing

    Laravel provides the Hash facade's make method for secure password hashing.
  2. Step 2: Compare options

    $hashed = Hash::make($password); is the recommended and most flexible method. bcrypt() helper is valid but less flexible. md5 and base64_encode are insecure.
  3. Final Answer:

    $hashed = Hash::make($password); -> Option A
  4. Quick Check:

    Password hashing = Hash::make() [OK]
Hint: Use Hash::make() for password hashing in Laravel [OK]
Common Mistakes:
  • Using insecure md5 or base64_encode
  • Confusing Hash::make without import
  • Saving passwords without hashing
3. Consider this Laravel route definition:
Route::middleware(['auth'])->group(function () {
    Route::get('/dashboard', function () {
        return 'Welcome to your dashboard';
    });
});
What will happen if a guest (not logged in) tries to access /dashboard?
medium
A. They will see the dashboard message
B. They will be redirected to the login page
C. They will get a 404 Not Found error
D. They will see a blank page

Solution

  1. Step 1: Understand the 'auth' middleware

    The 'auth' middleware restricts access to authenticated users only.
  2. Step 2: Behavior for guests

    If a guest tries to access a route with 'auth' middleware, Laravel redirects them to the login page.
  3. Final Answer:

    They will be redirected to the login page -> Option B
  4. Quick Check:

    Auth middleware redirects guests [OK]
Hint: Auth middleware redirects guests to login [OK]
Common Mistakes:
  • Assuming guests see the dashboard
  • Expecting 404 error instead of redirect
  • Thinking middleware shows blank page
4. This Laravel controller method is intended to validate user input securely:
public function store(Request $request) {
    $data = $request->validate([
        'email' => 'required|email',
        'password' => 'required|min:8'
    ]);
    User::create($data);
}
What is the main security issue here?
medium
A. Passwords are not hashed before saving
B. Email validation rule is incorrect
C. Validation rules are missing CSRF token check
D. User::create() should be User::update()

Solution

  1. Step 1: Check validation rules

    The validation correctly checks email and password format.
  2. Step 2: Check password handling

    The password is saved directly without hashing, which is insecure.
  3. Final Answer:

    Passwords are not hashed before saving -> Option A
  4. Quick Check:

    Passwords must be hashed before saving [OK]
Hint: Always hash passwords before saving to database [OK]
Common Mistakes:
  • Assuming validation hashes passwords
  • Confusing CSRF with validation rules
  • Thinking create() vs update() affects security here
5. You want to protect an API route in Laravel so only authenticated users with the role 'admin' can access it. Which is the best approach?
hard
A. Use 'auth' middleware and check role inside the controller method
B. Use 'guest' middleware and check role in middleware
C. No middleware needed; check role in the route definition
D. Use 'auth' middleware and create a custom middleware to check 'admin' role

Solution

  1. Step 1: Understand middleware roles

    'auth' middleware ensures user is logged in; role checks require custom logic.
  2. Step 2: Best practice for role checks

    Create a custom middleware to check if the authenticated user has 'admin' role, then apply both middlewares.
  3. Final Answer:

    Use 'auth' middleware and create a custom middleware to check 'admin' role -> Option D
  4. Quick Check:

    Combine auth + custom role middleware [OK]
Hint: Combine auth middleware with custom role middleware [OK]
Common Mistakes:
  • Using 'guest' middleware for authenticated routes
  • Checking roles only inside controller
  • Skipping middleware for role checks