Skip to content

Validation

use Naluz\Validation\Validator;
$data = Validator::make(Request::input($request), [
'title' => 'required|string|max:200',
'email' => 'required|email|unique:users,email',
'tags' => 'array',
'tags.*' => 'string|max:30',
])->validate();

validate() returns only the fields that have rules, so Post::create($validator->validate()) cannot be polluted by extra input. On failure it throws a ValidationException, which is rendered automatically (see below).

Method Purpose
Validator::make($data, $rules, $messages = [], $db = null) create a validator
->validate() returns validated data or throws ValidationException
->passes() / ->fails() boolean checks
->errors() array<string, list<string>>
->validated() the validated subset
Rule Passes when
required present and not null, '' or [] (false, 0 and '0' count as present)
nullable, sometimes the field may be missing or empty; remaining rules are skipped
string, integer, numeric, boolean, array the value has that type (integer accepts digit strings)
email, url, date, uuid valid format (url must be http or https)
alpha, alpha_num, alpha_dash Unicode letters, digits, dashes and underscores
min:n, max:n, between:a,b size: string length, array count, or the number when the field is also integer / numeric
in:a,b, not_in:a,b the value is (not) one of the list
regex:/pattern/ matches the pattern
confirmed equals <field>_confirmation
same:other, different:other equals / differs from another field
unique:table,column,ignoreId,idColumn no row has this value (optionally ignoring one row)
exists:table,column a row has this value

An unknown rule throws InvalidArgumentException, so typos fail loudly instead of silently passing.

A rule list may contain closures that return an error message, or null when valid:

'code' => ['required', fn ($value, $field, $data) => $value === 'secret' ? null : 'Wrong code.'],

Dotted paths (address.city) and * wildcards (items.*.qty) are supported.

unique and exists need a connection:

Validator::make($input, [
'email' => 'required|email|unique:users,email,' . $user->id, // ignore the current user
], db: $db->connection());

These checks always read from the primary database, so replication lag cannot allow duplicates.

Validator::make($data, $rules, [
'required' => 'Please fill in :field.', // per rule
'title.max' => 'The title is too long (max :0).', // per field and rule
]);

:field is the field name (underscores become spaces) and :0, :1 are the rule parameters.

A ValidationException is converted by the exception handler:

  • JSON clients (Accept: application/json, a JSON body, or /api paths): 422 with

    { "message": "The given data was invalid.", "errors": { "title": ["The title field is required."] } }
  • Browsers: a 303 redirect back to the previous page of the same site, with flashed errors and old input (fields whose names contain password, _token or secret are excluded).

Catch it yourself when you need custom handling:

$validator = Validator::make($data, $rules);
if ($validator->fails()) {
return Response::json(['problems' => $validator->errors()], 400);
}