Security Protections
SQL injection
Section titled “SQL injection”Every value is a bound parameter. Identifiers and operators are validated. See Query builder.
All web routes use the VerifyCsrfToken middleware. Unsafe methods (POST, PUT, PATCH, DELETE) need a token in the
_token form field or an X-CSRF-TOKEN header equal to the session token. If the request carries an Origin header it must match the host.
A failure returns 419.
In templates:
<form method="POST" action="/posts">@csrf …</form>or csrf_field() and csrf_token() in PHP. API routes are cookie-less and use bearer tokens instead.
Security headers
Section titled “Security headers”The global SecurityHeaders middleware sets these on every response:
X-Content-Type-OptionsX-Frame-OptionsReferrer-PolicyPermissions-PolicyCross-Origin-Opener-Policy- a restrictive
Content-Security-Policy(it forbids inline scripts and styles; loosen it deliberately) - HSTS when the request is HTTPS
Override or disable any header in config/security.php:
'headers' => [ 'Content-Security-Policy' => "default-src 'self'; img-src 'self' data:", 'X-Frame-Options' => null, // null disables a default header],Cross-origin requests are refused until you allow origins:
'cors' => [ 'allowed_origins' => ['https://app.example.com'], // empty disables CORS 'allowed_methods' => ['GET', 'POST', 'PUT', 'PATCH', 'DELETE'], 'allowed_headers' => ['Content-Type', 'Authorization', 'X-Requested-With'], 'exposed_headers' => [], 'supports_credentials' => false, 'max_age' => 600,],Rate limiting
Section titled “Rate limiting”->middleware('throttle:5,1') allows 5 requests per minute per IP and path. See Middleware.
Mass assignment
Section titled “Mass assignment”A model accepts nothing until $fillable lists the fields. forceFill() bypasses it and must never be fed raw request data.
Open redirects
Section titled “Open redirects”Response::redirect() rejects CR/LF, and validation redirects only go back to a path on the same host.
Uploads
Section titled “Uploads”Files are checked by content and stored under random names. See File storage.
Outbound requests
Section titled “Outbound requests”The HTTP client refuses private and loopback addresses on every hop. See HTTP client.
Reverse proxies
Section titled “Reverse proxies”REMOTE_ADDR is the proxy’s address behind a reverse proxy. Configure your web server to restore the real client IP rather
than trusting X-Forwarded-For. This matters for rate limiting and logs.