
Securing Laravel has moved!
You can find the new site at securinglaravel.com!
IMPORTANT: Securing Laravel has moved to https://securinglaravel.com!
Dormant Last read · last published · next check
Read 4 days ago and current, but nothing has been published for 2 years.

You can find the new site at securinglaravel.com!

Did you receive the Part 1 email from Ghost?

Just a quick note to let you know what to expect.

[Tip#78] Up until now, Laravel has only supported rate limiting per-minute, but that didn't work in some scenarios, as a minute is a very long time. To solve this, Laravel 11 supports per-second!

[Tip#77] We often talk about validating user input from the browser, but what about user input on the command line? Validation is just as useful there too!

[Tip#76] Let's check out three of the configuration options available as part of Automatic Password Rehashing: custom fields, disabling rehashing, and changing bcrypt rounds.

[InDepth#25] Laravel makes effective use of encryption for security purposes, but what happens if your encryption key needs to be rotated? Let's see how Laravel 11 handles it...

[Tip#75] As part of the simplification of the app structure in Laravel 11, the Request Authorisation and Validation methods are no longer available on the controller - here's how you get it back.

[Tip#74] Laravel 11 shifts the default middleware into the framework itself and exposes configuration through the bootstrap/app.php class.

[Tip#73] You may have heard of the `/.well-known/` path, and the security.txt file, but there is a new one called `change-password` you should be aware of too!