Laravel 12 Authentication: Secure Your App Like a Pro!
Ever worried about hackers breaking into your Laravel app? π Whether you're building a simple blog or a full-scale SaaS platform, authentication is your app's first line of defense.
Laravel 12 makes authentication easy, secure, and customizable. In this guide, weβll cover:
β
Built-in Auth Systems (Breeze, Jetstream, Sanctum)
β
Custom Authentication (Manual Login & Registration)
β
Advanced Security (2FA, Rate Limiting, Password Hashing)
Letβs lock things down! π
π₯ Why Authentication Matters
Before diving into code, let's understand why authentication is crucial:
β Protects User Data β Prevents unauthorized access.
β Prevents Attacks β Blocks brute force & credential stuffing.
β Enhances Trust β Users feel safe using your app.
π 1. Laravelβs Built-in Auth Solutions
Laravel offers three powerful tools for authentication:
πΉ Laravel Breeze (Simple & Lightweight)
Perfect for beginners! It includes:
- Login/Registration
- Password Reset
- Email Verification
Installation:
composer require laravel/breeze --dev
php artisan breeze:install
npm install && npm run dev
php artisan migrate
πΉ Laravel Jetstream (Advanced Features)
Need more? Jetstream adds:
- Two-Factor Authentication (2FA)
- API Support (Sanctum)
- Team Management
Installation:
composer require laravel/jetstream
php artisan jetstream:install livewire
npm install && npm run dev
php artisan migrate
πΉ Laravel Sanctum (API Authentication)
Building a mobile app or SPA? Sanctum provides token-based auth.
Installation:
composer require laravel/sanctum
php artisan sanctum:install
php artisan migrate
π 2. Custom Authentication (Manual Setup)
Sometimes, you need full control. Letβs build auth from scratch!
πΉ Step 1: Create Login & Register Routes
// routes/web.php
Route::get('/register', [AuthController::class, 'showRegister'])->name('register');
Route::post('/register', [AuthController::class, 'register']);
Route::get('/login', [AuthController::class, 'showLogin'])->name('login');
Route::post('/login', [AuthController::class, 'login']);
Route::post('/logout', [AuthController::class, 'logout'])->name('logout');
πΉ Step 2: Build the Auth Controller
// app/Http/Controllers/AuthController.php
public function register(Request $request)
{
$validated = $request->validate([
'name' => 'required|string|max:255',
'email' => 'required|email|unique:users',
'password' => 'required|confirmed|min:8',
]);
$user = User::create([
'name' => $validated['name'],
'email' => $validated['email'],
'password' => Hash::make($validated['password']),
]);
Auth::login($user);
return redirect('/dashboard');
}
public function login(Request $request)
{
$credentials = $request->validate([
'email' => 'required|email',
'password' => 'required',
]);
if (Auth::attempt($credentials)) {
return redirect('/dashboard');
}
return back()->withErrors(['email' => 'Invalid credentials!']);
}
πΉ Step 3: Protect Routes with Middleware
Route::middleware('auth')->group(function () {
Route::get('/dashboard', [DashboardController::class, 'index']);
});
π¨ 3. Advanced Security Measures
πΉ Two-Factor Authentication (2FA)
Use Laravel Fortify or Jetstream for 2FA.
Example (Fortify):
composer require laravel/fortify
php artisan vendor:publish --provider="Laravel\Fortify\FortifyServiceProvider"
πΉ Rate Limiting (Prevent Brute Force Attacks)
// app/Http/Middleware/ThrottleLogins.php
Route::post('/login', [AuthController::class, 'login'])
->middleware('throttle:5,1'); // 5 attempts per minute
πΉ Password Hashing (Never Store Plain Text!)
Laravel automatically hashes passwords using bcrypt:
$user->password = Hash::make('secure123');
π 4. Testing Your Authentication
β Manual Testing β Try logging in with wrong credentials.
β PHPUnit Testing β Automate security checks.
Example Test:
public function test_login_fails_with_wrong_password()
{
$user = User::factory()->create();
$response = $this->post('/login', [
'email' => $user->email,
'password' => 'wrongpass',
]);
$response->assertSessionHasErrors();
}
π― Key Takeaways
β Use Breeze/Jetstream for quick setup
β Build custom auth for full control
β Enable 2FA & rate limiting for security
β Always hash passwords
β Test authentication flows
π Final Thoughts
Laravel 12 makes authentication effortless and secure. Whether you use Breeze, Jetstream, or custom auth, your app will be locked down tight.
Got questions? Drop a comment below! π¬π
Happy coding! π»π₯
Projects to explore next
Source-code projects from the KritiMyantra catalogue. Check each project's details before buying.
Flask Authentication System (Free Version) - Kritim Yantra
π Featuresβ Google & GitHub Authenticationβ User Registration & Loginβ Profile/Dashboard Accessβ Secure & Mi...
Python Flask Blog Project with Admin Panel
Are you ready to launch a powerful, modern, and fully customizable blog? Look no further! Introducing the Flask-Blog Pro...
Laravel 12 + ReactJS Starter Kit: Add Multi-Language Support (Arabic, English, Spanish) with Blog CRUD
π Installation & Setup Download & Extract Get the ZIP from kritimyantra.com and extract it. Includes preconfigu...
Comments
No comments yet. Be the first to comment.
Sign in to join the discussion.