Skip to content
Back to skills

Laravel Sessions Middleware

ASecurity

Assuming `SecurityHeaders` exists at `app/Http/Middleware/SecurityHeaders.php`, register it globally in `bootstrap/app.php`: ```php <?php use App\Http\Middleware\SecurityHeaders; use Illuminate\Foundation\Application; use Illuminate\Foundation\Configuration\Middleware; return Application::configure(basePath: dirname(__DIR__)) ->withRouting( web: __DIR__.'/../routes/web.php', commands: __DIR__.'/../routes/console.php', health: '/up', ) ->withMiddleware(function (Middleware $middleware): void {...

  • 549 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
developmentphpsecurity

Security analysis

A100/100

Pro scans all 18 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill laravel-sessions-middleware --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Laravel Sessions Middleware?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Laravel Sessions Middleware
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-laravel-sessions-middleware-abbf7b9c/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-laravel-sessions-middleware-abbf7b9c)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
Assuming `SecurityHeaders` exists at `app/Http/Middleware/SecurityHeaders.php`, register it globally in `bootstrap/app.php`:

```php
<?php

use App\Http\Middleware\SecurityHeaders;
use Illuminate\Foundation\Application;
use Illuminate\Foundation\Configuration\Middleware;

return Application::configure(basePath: dirname(__DIR__))
    ->withRouting(
        web: __DIR__.'/../routes/web.php',
        commands: __DIR__.'/../routes/console.php',
        health: '/up',
    )
    ->withMiddleware(function (Middleware $middleware): void {
        $middleware->append(SecurityHeaders::class);

        // Use prepend() when this middleware must run at the highest priority.
        // $middleware->prepend(SecurityHeaders::class);
    })
    ->withExceptions(function ($exceptions): void {
        //
    })
    ->create();
```

`SecurityHeaders` should add HSTS, CSP, `X-Frame-Options`, and `X-Content-Type-Options`. Keep the middleware lightweight, cheap and deterministic; avoid heavy computation in the global pipeline. Use Redis in scaled production to avoid file-session I/O and locking problems, and regenerate the session after login to prevent session fixation.

Files in this skill

  • eval-1.baseline.md718 B
  • eval-1.with-skill.md958 B
  • eval-2.baseline.md1.2 KB
  • eval-2.with-skill.md1.9 KB
  • eval-3.baseline.md2 KB
  • eval-3.with-skill.md1.6 KB
  • eval-4.baseline.md910 B
  • eval-4.with-skill.md573 B
  • eval-5.baseline.md704 B
  • eval-5.with-skill.md1.1 KB
  • eval-6.baseline.md716 B
  • eval-6.with-skill.md900 B
  • trigger-1.md102 B
  • trigger-2.md167 B
  • trigger-3.md140 B
  • trigger-4.md143 B
  • trigger-5.md155 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…