Best fit
- Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署。
affaan-m/ECC
Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署。
npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/laravel-security"Source checked Jul 28, 2026·Refresh due Oct 26, 2026
Reorganized from the pinned upstream SKILL.md
According to the pinned SKILL.md from affaan-m/ECC: 针对 Laravel 应用程序的全面安全指导,以防范常见漏洞。
npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/laravel-security"Best fit
Bring this context
Expected outputs
Key source sections
Sections are extracted automatically from the pinned SKILL.md and link back to the source.
添加身份验证或授权时 处理用户输入和文件上传时 构建新的 API 端点时 管理密钥和环境设置时 强化生产环境部署时
中间件提供基础保护(通过 VerifyCsrfToken 实现 CSRF,通过 SecurityHeaders 实现安全标头)。 守卫和策略强制执行访问控制(auth:sanctum、$this-authorize、策略中间件)。 表单请求在输入到达服务之前进行验证和整形(UploadInvoiceRequest)。 速率限制在身份验证控制之外增加滥用保护(RateLimiter::for('login'))。 数据安全来自加密转换、批量赋值保护以及签名路由(URL::temporarySignedRoute + signed 中间件)。
生产环境中设置 APPDEBUG=false APPKEY 必须设置,并在泄露时轮换 设置 SESSIONSECURECOOKIE=true 和 SESSIONSAMESITE=lax(对于敏感应用,使用 strict) 配置受信任的代理以正确检测 HTTPS
设置 SESSIONHTTPONLY=true 以防止 JavaScript 访问 对高风险流程使用 SESSIONSAMESITE=strict 在登录和权限变更时重新生成会话
使用 Laravel Sanctum 或 Passport 进行 API 身份验证 对于敏感数据,优先使用带有刷新流程的短期令牌 在注销和账户泄露时撤销令牌
SkillSignal prompt templates
These prompts were written by SkillSignal from the source structure; they are not upstream text.
Task-start prompt
Confirm source fit, inputs, and outputs before acting.
Use laravel-security to help me with: [specific task]. Context: [files, data, or background]. Constraints: [environment, scope, and prohibited actions]. Before acting, check the pinned SKILL.md and explain which sections apply, what inputs are still missing, and what you will deliver.
Source-guided execution
Make the Agent explicitly follow the key extracted sections.
Apply the pinned laravel-security source to [task]. Pay particular attention to these source sections: “何时启用”, “工作原理”, “核心安全设置”, “会话和 Cookie 强化”, “身份验证与令牌”. Preserve the important decision at each step. Mark facts not covered by the source as “needs confirmation” instead of inventing them. Then verify the result against my acceptance criteria: [criteria].
Result-review prompt
Check omissions, permissions, and source drift before delivery.
Review the current laravel-security result: (1) does it satisfy the original task; (2) were any applicable steps or limits in the pinned SKILL.md missed; (3) did it perform any unauthorized file, command, network, or data action; and (4) which conclusions remain unverified? List issues first, then fix only what the source or user authorization supports.
Output checklist
The task matches the purpose documented in the SKILL.md.
The source section “何时启用” has been checked.
The source section “工作原理” has been checked.
The source section “核心安全设置” has been checked.
The source section “会话和 Cookie 强化” has been checked.
Inputs, constraints, and acceptance criteria are explicit.
Unverified facts, compatibility, and outcome claims are clearly marked.
Any file, command, network, or data action has been reviewed.
Choose a different workflow
Laravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations.
A separate implementation from affaan-m/ECC; compare its source, maintenance signals, and permission requirements.
Open source detailBuenas prácticas de seguridad en Laravel para autenticación/autorización, validación, CSRF, asignación masiva, subida de archivos, secretos, limitación de velocidad y despliegue seguro.
A separate implementation from affaan-m/ECC; compare its source, maintenance signals, and permission requirements.
Open source detailLaravel セキュリティベストプラクティス:認証・認可、バリデーション、CSRF、一括割当、ファイルアップロード、シークレット管理、レート制限、安全なデプロイメント
A separate implementation from affaan-m/ECC; compare its source, maintenance signals, and permission requirements.
Open source detailFAQ
针对 Laravel 应用程序的全面安全指导,以防范常见漏洞。
The catalog detected this source-specific install command: npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/laravel-security". Inspect the command and pinned source before running it.
No dedicated Agent platform is declared in the pinned source record.
Quality breakdown
Based on traceable docs and repository signals; stars are not treated as quality.
Compare before choosing
These links are selected from shared tasks, functions, stacks, platforms, and same-name variants. Compare the source owner, documentation, permissions, and maintenance signals.
Laravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations.
Buenas prácticas de seguridad en Laravel para autenticación/autorización, validación, CSRF, asignación masiva, subida de archivos, secretos, limitación de velocidad y despliegue seguro.
Laravel セキュリティベストプラクティス:認証・認可、バリデーション、CSRF、一括割当、ファイルアップロード、シークレット管理、レート制限、安全なデプロイメント
Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
Distributed computing for larger-than-RAM pandas/NumPy workflows. Use when you need to scale existing pandas/NumPy code beyond memory or across clusters. Best for parallel file processing, distributed ML, integration with existing pandas code. For out-of-core analytics on single machine use vaex; for in-memory speed use polars.
针对 Laravel 应用程序的全面安全指导,以防范常见漏洞。
VerifyCsrfToken 实现 CSRF,通过 SecurityHeaders 实现安全标头)。auth:sanctum、$this->authorize、策略中间件)。UploadInvoiceRequest)。RateLimiter::for('login'))。URL::temporarySignedRoute + signed 中间件)。APP_DEBUG=falseAPP_KEY 必须设置,并在泄露时轮换SESSION_SECURE_COOKIE=true 和 SESSION_SAME_SITE=lax(对于敏感应用,使用 strict)SESSION_HTTP_ONLY=true 以防止 JavaScript 访问SESSION_SAME_SITE=strict路由保护示例:
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Route;
Route::middleware('auth:sanctum')->get('/me', function (Request $request) {
return $request->user();
});
Hash::make() 哈希密码,切勿存储明文use Illuminate\Support\Facades\Hash;
use Illuminate\Validation\Rules\Password;
$validated = $request->validate([
'password' => ['required', 'string', Password::min(12)->letters()->mixedCase()->numbers()->symbols()],
]);
$user->update(['password' => Hash::make($validated['password'])]);
$this->authorize('update', $project);
使用策略中间件进行路由级强制执行:
use Illuminate\Support\Facades\Route;
Route::put('/projects/{project}', [ProjectController::class, 'update'])
->middleware(['auth:sanctum', 'can:update,project']);
$fillable 或 $guarded,避免使用 Model::unguard()DB::select('select * from users where email = ?', [$email]);
{{ }}){!! !!}VerifyCsrfToken 中间件启用@csrf,并为 SPA 请求发送 XSRF 令牌对于使用 Sanctum 的 SPA 身份验证,确保配置了有状态请求:
// config/sanctum.php
'stateful' => explode(',', env('SANCTUM_STATEFUL_DOMAINS', 'localhost')),
final class UploadInvoiceRequest extends FormRequest
{
public function authorize(): bool
{
return (bool) $this->user()?->can('upload-invoice');
}
public function rules(): array
{
return [
'invoice' => ['required', 'file', 'mimes:pdf', 'max:5120'],
];
}
}
$path = $request->file('invoice')->store(
'invoices',
config('filesystems.private_disk', 'local') // set this to a non-public disk
);
throttle 中间件use Illuminate\Cache\RateLimiting\Limit;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\RateLimiter;
RateLimiter::for('login', function (Request $request) {
return [
Limit::perMinute(5)->by($request->ip()),
Limit::perMinute(5)->by(strtolower((string) $request->input('email'))),
];
});
对静态的敏感列使用加密转换。
protected $casts = [
'api_token' => 'encrypted',
];
设置标头的中间件示例:
use Illuminate\Http\Request;
use Symfony\Component\HttpFoundation\Response;
final class SecurityHeaders
{
public function handle(Request $request, \Closure $next): Response
{
$response = $next($request);
$response->headers->add([
'Content-Security-Policy' => "default-src 'self'",
'Strict-Transport-Security' => 'max-age=31536000', // add includeSubDomains/preload only when all subdomains are HTTPS
'X-Frame-Options' => 'DENY',
'X-Content-Type-Options' => 'nosniff',
'Referrer-Policy' => 'no-referrer',
]);
return $response;
}
}
config/cors.php 中限制来源// config/cors.php
return [
'paths' => ['api/*', 'sanctum/csrf-cookie'],
'allowed_methods' => ['GET', 'POST', 'PUT', 'PATCH', 'DELETE'],
'allowed_origins' => ['https://app.example.com'],
'allowed_headers' => [
'Content-Type',
'Authorization',
'X-Requested-With',
'X-XSRF-TOKEN',
'X-CSRF-TOKEN',
],
'supports_credentials' => true,
];
use Illuminate\Support\Facades\Log;
Log::info('User updated profile', [
'user_id' => $user->id,
'email' => '[REDACTED]',
'token' => '[REDACTED]',
]);
composer audit使用签名路由生成临时的、防篡改的链接。
use Illuminate\Support\Facades\URL;
$url = URL::temporarySignedRoute(
'downloads.invoice',
now()->addMinutes(15),
['invoice' => $invoice->id]
);
use Illuminate\Support\Facades\Route;
Route::get('/invoices/{invoice}/download', [InvoiceController::class, 'download'])
->name('downloads.invoice')
->middleware('signed');