Jump into concepts and practice - no test required
or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What is CSRF protection in Laravel?
CSRF (Cross-Site Request Forgery) protection prevents unauthorized commands from being transmitted from a user that the web application trusts. Laravel uses a CSRF token in forms to verify requests are genuine.
Click to reveal answer
beginner
How does Laravel help prevent SQL Injection?
Laravel uses prepared statements and query builder which automatically bind parameters. This prevents attackers from injecting malicious SQL code.
Click to reveal answer
beginner
Why should you never store passwords in plain text in Laravel?
Storing passwords in plain text risks user data if the database is leaked. Laravel provides bcrypt hashing to securely store passwords so they cannot be read directly.
Click to reveal answer
intermediate
What is the purpose of Laravel's 'Encrypt Cookies' middleware?
It encrypts cookies so that their contents cannot be read or tampered with by users, protecting sensitive data stored in cookies.
Click to reveal answer
intermediate
How can you secure file uploads in Laravel?
Validate file types and sizes, store files outside the public directory, and use Laravel's storage system to control access. This prevents malicious files from harming the app.
Click to reveal answer
Which Laravel feature helps prevent Cross-Site Request Forgery attacks?
ABlade templating
BEloquent ORM
CCSRF token
DRoute caching
✗ Incorrect
CSRF tokens are used to verify that form submissions come from your application, preventing CSRF attacks.
What does Laravel use to securely hash passwords?
ASHA1
BMD5
CBase64
Dbcrypt
✗ Incorrect
Laravel uses bcrypt hashing which is strong and slow, making password cracking difficult.
How does Laravel protect against SQL Injection?
AUsing prepared statements and query builder
BEncrypting database tables
CDisabling database access
DUsing raw SQL queries only
✗ Incorrect
Prepared statements separate SQL code from data, preventing injection attacks.
Which middleware encrypts cookies in Laravel?
AEncryptCookies
BVerifyCsrfToken
CAuthenticate
DThrottleRequests
✗ Incorrect
EncryptCookies middleware encrypts cookie data to protect it from tampering.
What is a good practice for securing file uploads in Laravel?
AStore files in public directory
BValidate file type and size
CAllow all file types
DDisable file uploads
✗ Incorrect
Validating file type and size helps prevent malicious files from being uploaded.
Explain how Laravel protects your application from Cross-Site Request Forgery (CSRF) attacks.
Think about how Laravel checks that form submissions are from your app.
You got /4 concepts.
Describe best practices for handling user passwords securely in Laravel.
Focus on how passwords should be stored and why.
You got /4 concepts.
Practice
(1/5)
1. Which Laravel feature helps protect your application from Cross-Site Request Forgery (CSRF) attacks?
easy
A. Storing passwords in plain text
B. Using raw SQL queries without bindings
C. CSRF tokens automatically added to forms
D. Disabling middleware in routes
Solution
Step 1: Understand CSRF attacks
CSRF attacks trick users into submitting unwanted requests. Laravel uses tokens to prevent this.
Step 2: Identify Laravel's protection method
Laravel automatically adds CSRF tokens to forms and verifies them on submission.
Final Answer:
CSRF tokens automatically added to forms -> Option C
Quick Check:
CSRF protection = CSRF tokens [OK]
Hint: CSRF protection means using tokens in forms [OK]
Common Mistakes:
Thinking raw SQL protects against CSRF
Disabling middleware removes security
Storing passwords in plain text is unsafe
2. Which of the following is the correct way to hash a password before saving it in Laravel?
Laravel provides the Hash facade's make method for secure password hashing.
Step 2: Compare options
$hashed = Hash::make($password); is the recommended and most flexible method. bcrypt() helper is valid but less flexible. md5 and base64_encode are insecure.
Final Answer:
$hashed = Hash::make($password); -> Option A
Quick Check:
Password hashing = Hash::make() [OK]
Hint: Use Hash::make() for password hashing in Laravel [OK]
Common Mistakes:
Using insecure md5 or base64_encode
Confusing Hash::make without import
Saving passwords without hashing
3. Consider this Laravel route definition:
Route::middleware(['auth'])->group(function () {
Route::get('/dashboard', function () {
return 'Welcome to your dashboard';
});
});
What will happen if a guest (not logged in) tries to access /dashboard?
medium
A. They will see the dashboard message
B. They will be redirected to the login page
C. They will get a 404 Not Found error
D. They will see a blank page
Solution
Step 1: Understand the 'auth' middleware
The 'auth' middleware restricts access to authenticated users only.
Step 2: Behavior for guests
If a guest tries to access a route with 'auth' middleware, Laravel redirects them to the login page.
Final Answer:
They will be redirected to the login page -> Option B
Quick Check:
Auth middleware redirects guests [OK]
Hint: Auth middleware redirects guests to login [OK]
Common Mistakes:
Assuming guests see the dashboard
Expecting 404 error instead of redirect
Thinking middleware shows blank page
4. This Laravel controller method is intended to validate user input securely:
public function store(Request $request) {
$data = $request->validate([
'email' => 'required|email',
'password' => 'required|min:8'
]);
User::create($data);
}
What is the main security issue here?
medium
A. Passwords are not hashed before saving
B. Email validation rule is incorrect
C. Validation rules are missing CSRF token check
D. User::create() should be User::update()
Solution
Step 1: Check validation rules
The validation correctly checks email and password format.
Step 2: Check password handling
The password is saved directly without hashing, which is insecure.
Final Answer:
Passwords are not hashed before saving -> Option A
Quick Check:
Passwords must be hashed before saving [OK]
Hint: Always hash passwords before saving to database [OK]
Common Mistakes:
Assuming validation hashes passwords
Confusing CSRF with validation rules
Thinking create() vs update() affects security here
5. You want to protect an API route in Laravel so only authenticated users with the role 'admin' can access it. Which is the best approach?
hard
A. Use 'auth' middleware and check role inside the controller method
B. Use 'guest' middleware and check role in middleware
C. No middleware needed; check role in the route definition
D. Use 'auth' middleware and create a custom middleware to check 'admin' role
Solution
Step 1: Understand middleware roles
'auth' middleware ensures user is logged in; role checks require custom logic.
Step 2: Best practice for role checks
Create a custom middleware to check if the authenticated user has 'admin' role, then apply both middlewares.
Final Answer:
Use 'auth' middleware and create a custom middleware to check 'admin' role -> Option D
Quick Check:
Combine auth + custom role middleware [OK]
Hint: Combine auth middleware with custom role middleware [OK]