Skip to content

Entries with the tag “laravel”

These entries contain content about programming efficient, effective and secure Laravel projects.

Want to become a better Laravel programmer? Check out masteringlaravel.io for ebooks, videos, tools and more - or listen to the dulcet tones of Joel and I talking Laravel on the No Compromises Podcast.

Why I'm Starting to Love Parallel Testing

Maybe I’m behind. But I like to think of it as conservative. Parallel unit testing has been around for a while, and I haven’t really reached for it until recently.

This isn’t about not wanting to change, though. It’s about using the proper tools for the job, and only when necessary.

Or at least, that’s how I rationalize my delay. But maybe you’re in the same place. Let’s dig into why I waited, why you might want to wait still, and the reasons why this works now.

Sep 14, 2026 4 min read #laravel #php #phpunit #testing

Validate Everything Including Pagination

There are many reasons why we validate data - whether it’s a Laravel project or any other framework or technology. Sometimes it’s for user or business sanity, other times to keep the application functioning properly. We even do so for security - for both security attacks we know about and hopefully to stop ones we don’t understand.

This is the reason why I reached for validation on pagination requests. This is user input. Just because I don’t understand how it could hurt me doesn’t mean I should ignore it, right?

Let’s validate pagination - easily - in Laravel.

May 26, 2026 2 min read #laravel #security

Laravel 201 Created JSON With Location Header

Each API seems to be different. However, there are some best practices that we should all try to follow.

One of those that I really like is the 201 Created HTTP response. If the object is created immediately, you may even return the full object contents.

In some cases, we don’t have the data or don’t want to return the full payload. We can return null with a location header. Here’s how to do that with Laravel.

Mar 12, 2026 1 min read #laravel

Customize Laravel Ide Helper to Autocomplete Blade Files

I’m working with Yajra DataTables in a Laravel project and I’ve ran into a little bit of a headache. They provide their own render() method, which you pass a blade file to as the first parameter. Something like users.dogs.index - and through that mechanism it loads the proper blade for the datatable.

Here’s the problem, though. I can’t get auto complete and I can’t click through on that in PhpStorm. But I want to. Let’s find out how.

Dec 17, 2025 2 min read #laravel #phpstorm

Stopping Laravel SQL Injection with sole()

I love using Eloquent’s sole() method in Laravel. It throws an exception if the result set is ever more than 1. It means you should only have a sole record. This is usually what I want. I’ve migrated away from firstOrFail() unless I legitimately want the first of a matching set.

But I just found another reason to love using the sole method - it helps add a layer of protection against SQL injection. Let’s find out how.

Nov 7, 2025 2 min read #laravel #mysql #security #sql

Why You Might Want to Hydrate Models to Delete Them in Laravel

There are many ways to handle cascading functionality in Laravel. You can do this with observers, events, manually dispatched jobs - even in MySQL with cascading deletes.

I prefer to keep my cascading logic in the application code by using Eloquent Model Events. This is super easy when it’s just a single level of model. But what about relationships?

Oct 15, 2025 2 min read #laravel

Livewire 3 Reactive Event Dispatching

Issuing events with Livewire is a useful way to communicate between components. But, there are some caveats to be aware of - especially if you’re coming from something like React or Vue. The majority of this comes from the fact that Livewire treats every component as an island.

This had stumped me a few times in the past. Because of this, I wanted to give a quick example of how you can use Livewire events in a way that you might be more familiar with: with reactivity.

Sep 9, 2025 3 min read #laravel

How I Launch a Laravel Testbed

Sometimes I need to spin up a quick Laravel instance on my Mac to test something out. With just a couple keystrokes, I can get a brand new Laravel instance running in a Docker container, ready for my IDE and testing. Here’s how.

Jan 16, 2025 2 min read #laravel

Laravel Display Markdown Easily in Blade

I love writing in Markdown - and offering that functionality in WYSIWYG editors for our users. But, it just seems so complicated to try to show markdown in Laravel blade files. So, I made a quick anonymous component that makes this easier.

Sep 2, 2024 2 min read #laravel

Laravel Log Throttled Users

You’ve got Laravel throttling set up on authentication, password reset and other sensitive endpoints. But, how do you know this is actually working to stop people? Or what if you either want to admonish bad users or proactively reach out with support to help them? Perhaps you might want to log your throttled attempts. It’s pretty easy.

Sep 1, 2024 2 min read #laravel #security

Laravel Log Incoming API Request and Response

There are packages out there to add logging to the HTTP client in Laravel for outgoing requests freely available. Those are great, but what about if you’re providing an API - and you need to log incoming requests and responses? There’s not a single place to do that - or is there? Let’s look at a middleware to log our incoming requests and responses.

Jul 21, 2024 2 min read #laravel

Generate Laravel Seeds Package Idea

When projects don’t have a proper set up of dev data using Laravel seeders, getting started can be kind of tough. And if you can help it, you really don’t want to be pulling data from production. User data is precious and should be protected! So what kind of package or utility could help us here? Let me detail out my thoughts - maybe it’s something you want to build!

Jun 21, 2024 2 min read #ideas #laravel

Laravel Password Reset a Little Better

There are a number of tools and packages that help you manage your users and their associated password reset flows available. The Laravel docs also describe a way that you can reset your password in your own controller. Depending on the use case of the application, I end up having to use code like this in some applications when other packages won’t work as drop-ins. But, can we make this example a little better, more secure, easier to read or a better UX? I think so. Let’s go.

Mar 27, 2024 5 min read #laravel #security #ux

Logging for Laravel Http Client

I’m a huge fan of using the Laravel HTTP Client for requests to third-party APIs. It’s clean and easy, nice for unit testing, and exposes methods for the most common functionality we need when consuming APIs. But one thing has bothered me - how do I log both my request and the API’s response, no matter what, with no special calls. Well, we’re in luck - using some global middleware on the client, we can do just that.

Jan 15, 2024 3 min read #laravel

Is a Laravel Blade Component for a Form a Good Idea?

The other day I was troubleshooting some code for a form in Laravel that was using a PUT method. Turns out the previous developer had not understood - and I had missed - that the @method override was missing. So I got to thinking - what if we made a form component that handles this for us? Is this a good idea?

Jun 5, 2023 3 min read #laravel

Get Laravel Auth User in 404 Blade

It’s nice that you can customize the 4xx/5xx error blade files if they’re published in Laravel - I like that. But what if you want to access the current user - or even use your standard layout - for the not found / 404 error? It’s actually quite easy. Let’s check it out.

May 6, 2023 2 min read #laravel

Sort Nova Users on Spatie Role

The specific challenge is to sort users in a Laravel Nova application by their role. For this specific example, though, we have a number of assumptions. Although this article solves this very specific problem, you can probably extend it to apply to other custom data challenges in Nova. Let’s check it out.

Apr 9, 2023 5 min read #laravel

Highlight Laravel Logs in PhpStorm

I’d like to say I don’t ever have tons of error logs in my Laravel projects - but, sometimes it happens. With a sea of text, how can you see what you need to see easily? Enter JetBrain’s idealog plugin in PhpStorm.

Jan 12, 2022 3 min read #laravel #phpstorm

Capture and redirect all Laravel email

First off, if you can use something like mailtrap I definitely recommend doing it. Mailtrap provides credentials and configuration so you can capture all of your email into a test inbox. But if that’s not possible, there is another option - and it has to do with Laravel’s mail events.

Dec 2, 2021 2 min read #laravel #php

Do Not Use Laravel Tinker in Production

I’ll say it again: do not install Laravel Tinker in production, and certainly do not use it. It’s a great tool to do work in your application, but only in test and development environments. That’s why I only install it in my require-dev section of my composer.json file.

Oct 19, 2021 4 min read #laravel #php

Reasons Why Not to Use Doctrine with Laravel

Currently, there are two pretty common packages for interacting with your database: Eloquent and Doctrine. Eloquent is part of Laravel and Doctrine, while used often on its own, is usually referenced with Symfony. If you’ve come to read this article, you’re probably versed in Doctrine and wondering why you can’t just - or shouldn’t just - use it with your new Laravel project.

Nov 16, 2019 6 min read #laravel #php

Filter User Input Before Validation in Laravel

Sometimes it makes sense to filter user input before it goes to validation. If you’re using controller-based validation in Laravel, this is pretty easy. But, if you’re doing your validation in request classes, your approach needs to be different.

Jun 6, 2019 2 min read #laravel #php

Two Gotchas in Laravel Unit Testing

There’s a struggle to balance the easy-to-use Laravel helpers and functions with very verbose, complicated methods in unit tests. As I’ve been relying on Laravel’s way of doing testing more, I’ve ran into a couple of gotchas that I should share.

May 20, 2019 2 min read #laravel #php #phpunit

Laravel 5 Middleware that Requires JSON

Laravel has a built in request helper called wantsJson() that determines if the request is requesting JSON with the Accept: application/json header. But, what if you want to only accept JSON responses? I set up a Laravel middleware that rejects anything that isn’t JSON.

Mar 18, 2019 1 min read #laravel #php

Keep Data Migrations Separate from Database Migration

By now, you’ve probably written many database migrations in Laravel. But, then something else happens. Perhaps your business model changed, your data attributes changed or you’re just refactoring to a stronger architecture. Doesn’t matter which, you’re going to need to convert and migrate some data.

Jan 7, 2019 3 min read #laravel #mysql #php

Quick Honey Pots in Laravel

When someone breaches the security of a web app, sometimes it’s not discovered to weeks or months later. There are a number of tools that specialize in intrusion detection, but they may be costly or difficult to set up. Another idea is to use a canary in the coal mine or a honey pot. Here we’ll talk about the concept and then demonstrate some easy and quick methods.

Aug 18, 2018 5 min read #laravel #php

Adding CSV Responses to Laravel Using Macros

Laravel has a lot of the most common functionality built into the framework. However, decisions need to be made to balance the needs of the majority of use cases with the stability and agility that programmers need. No one really wants a bloated library. Because of this, you might find that you need functionality that is not directly built into Laravel. When I started working with Laravel-based CSV responses, this was the case. (This article is based on Laravel 5.6.)

Aug 3, 2018 4 min read #laravel #php

Laravel 5.4 API/Request Validate Boolean

For some API work in Laravel, I wanted to validate that the incoming request parameter was a boolean value. At first I tried using the built in boolean slug validator but it didn’t accept all of the ‘boolean’ values I wanted to use. (Also there were weird scenarios where string values of false were triggering as true - like what I wrote about here.

Nov 17, 2017 1 min read #laravel #php

Validate Request Parameter Not Present in Laravel 5.4

You can make use of guarded or fillable attributes in Eloquent models in Laravel to help control what values you might allow to be updated via your API. But, I wanted to go a step further and actually stop certain values from being passed in. You could go pretty wild with this and try to block everything, but that’s not what I did. I made this validator.

Nov 17, 2017 2 min read #laravel #php

For Performance, Skip Generating Hashes in Laravel Factories

This isn’t a one-size-fits-all suggestion, but it’s a start to help you think about how you actually interact with factories in Laravel. They are used for test data, and are ran very often, multiple times in a row. You don’t need as much random information as you need. (In fact, a lot of times I see people overusing Faker even.)

Nov 15, 2017 1 min read #laravel #php

Laravel Pretty Print JSON Middleware

For testing, I tend to use Postman - which gives you the option to view your API JSON responses in a preview mode (interactive), pretty and raw. But, the other day I heard someone saying sometimes they just want to invoke pretty print in their JSON responses without having to use an external tool and set up a whole environment.

Nov 14, 2017 2 min read #laravel #php

Studly Words in Laravel

In Laravel, the Support\Str class has a lot of useful methods for switching formats of strings between each other. I needed to take a hyphenated slug and change it to title case words. In Laravel land, I think this is referred to as “Studly” - because I found something very similar called Str::studly(). This converts underline or hyphenated words into a single string with capital letters. I wanted to not concatenate all of these.

Oct 25, 2017 1 min read #laravel #php

Use Dependency Injection in Laravel Console Commands

It’s important to unit test your application code - even your console commands. So many times, I’ve seen people using the Artisan facade inside of console commands to either queue up new commands or call a different command. This makes it more difficult to unit test the application - you have to rely more on fakery (requiring you to reset your application each time then) and/or integration tests.

Sep 23, 2017 2 min read #laravel #php #testing

Easily Test JSON Keys in Laravel API Response

In my Laravel application, I have an end point that will retrieve a collection of Client models. I have many other unit tests that validate that my repository returns the proper clients when requested, that my client model is sound. My last test is a feature test checks that if I retrieve a list of clients from the end point there is proper pagination and client models exist. I don’t really need to test the exact values because I know this will work - from all my other tests.

Jun 27, 2017 2 min read #laravel #php #phpunit

Laravel Log Database Queries Based On Environment Variable

A nice feature of Laravel is the ability to add a listener to the DB object’s events (or SQL queries). I’ve seen some people add this, then comment it out when it’s done, then un-comment it if they need it again. I don’t like that - I don’t want commented code in my files (also that’s why we have version control).

Jun 6, 2017 2 min read #laravel #php

Issue 404 Not Found Middleware After Pagination Limit

A pet-peeve of mine is pagination that doesn’t work properly. One that I ran into lately with Laravel is related to the pagination system it has built in. I was able to request pages that were larger than the last page with no discernible error. So, I decided to write a middleware to handle this issue for all of my content.

Jun 1, 2017 2 min read #laravel #php