affaan-m/ECC

laravel-security

Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署。

76CollectingNetwork access
See how to use itView GitHub source
npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/laravel-security"
Automated source guide

Source checked Jul 28, 2026·Refresh due Oct 26, 2026

Reorganized from the pinned upstream SKILL.md

Turn laravel-security's source instructions into a guide you can follow

According to the pinned SKILL.md from affaan-m/ECC: 针对 Laravel 应用程序的全面安全指导,以防范常见漏洞。

npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/laravel-security"
Check the pinned source

Best fit

  • Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署。

Bring this context

  • A concrete task that matches the documented purpose of laravel-security.
  • The files, examples, or context the task depends on.
  • Your constraints, target environment, and definition of done.

Expected outputs

  • A result that follows the pinned laravel-security instructions.
  • A concise record of assumptions, inputs used, and unresolved questions.
  • A final check against the source workflow and relevant permission signals.

Key source sections

Read laravel-security through these 5 source sections

Sections are extracted automatically from the pinned SKILL.md and link back to the source.

01

何时启用

添加身份验证或授权时 处理用户输入和文件上传时 构建新的 API 端点时 管理密钥和环境设置时 强化生产环境部署时

SKILL.md · 何时启用
添加身份验证或授权时处理用户输入和文件上传时构建新的 API 端点时
02

工作原理

中间件提供基础保护(通过 VerifyCsrfToken 实现 CSRF,通过 SecurityHeaders 实现安全标头)。 守卫和策略强制执行访问控制(auth:sanctum、$this-authorize、策略中间件)。 表单请求在输入到达服务之前进行验证和整形(UploadInvoiceRequest)。 速率限制在身份验证控制之外增加滥用保护(RateLimiter::for('login'))。 数据安全来自加密转换、批量赋值保护以及签名路由(URL::temporarySignedRoute + signed 中间件)。

SKILL.md · 工作原理
中间件提供基础保护(通过 VerifyCsrfToken 实现 CSRF,通过 SecurityHeaders 实现安全标头)。守卫和策略强制执行访问控制(auth:sanctum、$this-authorize、策略中间件)。表单请求在输入到达服务之前进行验证和整形(UploadInvoiceRequest)。
03

核心安全设置

生产环境中设置 APPDEBUG=false APPKEY 必须设置,并在泄露时轮换 设置 SESSIONSECURECOOKIE=true 和 SESSIONSAMESITE=lax(对于敏感应用,使用 strict) 配置受信任的代理以正确检测 HTTPS

SKILL.md · 核心安全设置
生产环境中设置 APPDEBUG=falseAPPKEY 必须设置,并在泄露时轮换设置 SESSIONSECURECOOKIE=true 和 SESSIONSAMESITE=lax(对于敏感应用,使用 strict)
04

会话和 Cookie 强化

设置 SESSIONHTTPONLY=true 以防止 JavaScript 访问 对高风险流程使用 SESSIONSAMESITE=strict 在登录和权限变更时重新生成会话

SKILL.md · 会话和 Cookie 强化
设置 SESSIONHTTPONLY=true 以防止 JavaScript 访问对高风险流程使用 SESSIONSAMESITE=strict在登录和权限变更时重新生成会话
05

身份验证与令牌

使用 Laravel Sanctum 或 Passport 进行 API 身份验证 对于敏感数据,优先使用带有刷新流程的短期令牌 在注销和账户泄露时撤销令牌

SKILL.md · 身份验证与令牌
使用 Laravel Sanctum 或 Passport 进行 API 身份验证对于敏感数据,优先使用带有刷新流程的短期令牌在注销和账户泄露时撤销令牌

SkillSignal prompt templates

Provide the task, context, and acceptance criteria

These prompts were written by SkillSignal from the source structure; they are not upstream text.

Task-start prompt

Confirm source fit, inputs, and outputs before acting.

Use laravel-security to help me with: [specific task]. Context: [files, data, or background]. Constraints: [environment, scope, and prohibited actions]. Before acting, check the pinned SKILL.md and explain which sections apply, what inputs are still missing, and what you will deliver.

Source-guided execution

Make the Agent explicitly follow the key extracted sections.

Apply the pinned laravel-security source to [task]. Pay particular attention to these source sections: “何时启用”, “工作原理”, “核心安全设置”, “会话和 Cookie 强化”, “身份验证与令牌”. Preserve the important decision at each step. Mark facts not covered by the source as “needs confirmation” instead of inventing them. Then verify the result against my acceptance criteria: [criteria].

Result-review prompt

Check omissions, permissions, and source drift before delivery.

Review the current laravel-security result: (1) does it satisfy the original task; (2) were any applicable steps or limits in the pinned SKILL.md missed; (3) did it perform any unauthorized file, command, network, or data action; and (4) which conclusions remain unverified? List issues first, then fix only what the source or user authorization supports.

Output checklist

Verify each item before delivery

The task matches the purpose documented in the SKILL.md.

The source section “何时启用” has been checked.

The source section “工作原理” has been checked.

The source section “核心安全设置” has been checked.

The source section “会话和 Cookie 强化” has been checked.

Inputs, constraints, and acceptance criteria are explicit.

Unverified facts, compatibility, and outcome claims are clearly marked.

Any file, command, network, or data action has been reviewed.

Choose a different workflow

When another Skill is the better fit

FAQ

What does laravel-security do?

针对 Laravel 应用程序的全面安全指导,以防范常见漏洞。

How do I start using laravel-security?

The catalog detected this source-specific install command: npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/laravel-security". Inspect the command and pinned source before running it.

Which Agent platforms does it declare?

No dedicated Agent platform is declared in the pinned source record.

Repository stars
234,327
Repository forks
35,711
Quality
76/100
Source repository last pushed

Quality breakdown

Based on traceable docs and repository signals; stars are not treated as quality.

76/100
Documentation26/30
Specificity14/25
Maintenance20/20
Trust signals16/25
View original Skill.mdThis page is parsed directly from the repository SKILL.md without editorial rewriting. Collected: Jul 28, 2026 · about 1 min

Laravel 安全最佳实践

针对 Laravel 应用程序的全面安全指导,以防范常见漏洞。

何时启用

  • 添加身份验证或授权时
  • 处理用户输入和文件上传时
  • 构建新的 API 端点时
  • 管理密钥和环境设置时
  • 强化生产环境部署时

工作原理

  • 中间件提供基础保护(通过 VerifyCsrfToken 实现 CSRF,通过 SecurityHeaders 实现安全标头)。
  • 守卫和策略强制执行访问控制(auth:sanctum$this->authorize、策略中间件)。
  • 表单请求在输入到达服务之前进行验证和整形(UploadInvoiceRequest)。
  • 速率限制在身份验证控制之外增加滥用保护(RateLimiter::for('login'))。
  • 数据安全来自加密转换、批量赋值保护以及签名路由(URL::temporarySignedRoute + signed 中间件)。

核心安全设置

  • 生产环境中设置 APP_DEBUG=false
  • APP_KEY 必须设置,并在泄露时轮换
  • 设置 SESSION_SECURE_COOKIE=trueSESSION_SAME_SITE=lax(对于敏感应用,使用 strict
  • 配置受信任的代理以正确检测 HTTPS

会话和 Cookie 强化

  • 设置 SESSION_HTTP_ONLY=true 以防止 JavaScript 访问
  • 对高风险流程使用 SESSION_SAME_SITE=strict
  • 在登录和权限变更时重新生成会话

身份验证与令牌

  • 使用 Laravel Sanctum 或 Passport 进行 API 身份验证
  • 对于敏感数据,优先使用带有刷新流程的短期令牌
  • 在注销和账户泄露时撤销令牌

路由保护示例:

use Illuminate\Http\Request;
use Illuminate\Support\Facades\Route;

Route::middleware('auth:sanctum')->get('/me', function (Request $request) {
    return $request->user();
});

密码安全

  • 使用 Hash::make() 哈希密码,切勿存储明文
  • 使用 Laravel 的密码代理进行重置流程
use Illuminate\Support\Facades\Hash;
use Illuminate\Validation\Rules\Password;

$validated = $request->validate([
    'password' => ['required', 'string', Password::min(12)->letters()->mixedCase()->numbers()->symbols()],
]);

$user->update(['password' => Hash::make($validated['password'])]);

授权:策略与门面

  • 使用策略进行模型级授权
  • 在控制器和服务中强制执行授权
$this->authorize('update', $project);

使用策略中间件进行路由级强制执行:

use Illuminate\Support\Facades\Route;

Route::put('/projects/{project}', [ProjectController::class, 'update'])
    ->middleware(['auth:sanctum', 'can:update,project']);

验证与数据清理

  • 始终使用表单请求验证输入
  • 使用严格的验证规则和类型检查
  • 切勿信任请求负载中的派生字段

批量赋值保护

  • 使用 $fillable$guarded,避免使用 Model::unguard()
  • 优先使用 DTO 或显式的属性映射

SQL 注入防范

  • 使用 Eloquent 或查询构建器的参数绑定
  • 除非绝对必要,避免使用原生 SQL
DB::select('select * from users where email = ?', [$email]);

XSS 防范

  • Blade 默认转义输出({{ }}
  • 仅对可信的、已清理的 HTML 使用 {!! !!}
  • 使用专用库清理富文本

CSRF 保护

  • 保持 VerifyCsrfToken 中间件启用
  • 在表单中包含 @csrf,并为 SPA 请求发送 XSRF 令牌

对于使用 Sanctum 的 SPA 身份验证,确保配置了有状态请求:

// config/sanctum.php
'stateful' => explode(',', env('SANCTUM_STATEFUL_DOMAINS', 'localhost')),

文件上传安全

  • 验证文件大小、MIME 类型和扩展名
  • 尽可能将上传文件存储在公开路径之外
  • 如果需要,扫描文件以查找恶意软件
final class UploadInvoiceRequest extends FormRequest
{
    public function authorize(): bool
    {
        return (bool) $this->user()?->can('upload-invoice');
    }

    public function rules(): array
    {
        return [
            'invoice' => ['required', 'file', 'mimes:pdf', 'max:5120'],
        ];
    }
}
$path = $request->file('invoice')->store(
    'invoices',
    config('filesystems.private_disk', 'local') // set this to a non-public disk
);

速率限制

  • 在身份验证和写入端点应用 throttle 中间件
  • 对登录、密码重置和 OTP 使用更严格的限制
use Illuminate\Cache\RateLimiting\Limit;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\RateLimiter;

RateLimiter::for('login', function (Request $request) {
    return [
        Limit::perMinute(5)->by($request->ip()),
        Limit::perMinute(5)->by(strtolower((string) $request->input('email'))),
    ];
});

密钥与凭据

  • 切勿将密钥提交到源代码管理
  • 使用环境变量和密钥管理器
  • 密钥暴露后及时轮换,并使会话失效

加密属性

对静态的敏感列使用加密转换。

protected $casts = [
    'api_token' => 'encrypted',
];

安全标头

  • 在适当的地方添加 CSP、HSTS 和框架保护
  • 使用受信任的代理配置来强制执行 HTTPS 重定向

设置标头的中间件示例:

use Illuminate\Http\Request;
use Symfony\Component\HttpFoundation\Response;

final class SecurityHeaders
{
    public function handle(Request $request, \Closure $next): Response
    {
        $response = $next($request);

        $response->headers->add([
            'Content-Security-Policy' => "default-src 'self'",
            'Strict-Transport-Security' => 'max-age=31536000', // add includeSubDomains/preload only when all subdomains are HTTPS
            'X-Frame-Options' => 'DENY',
            'X-Content-Type-Options' => 'nosniff',
            'Referrer-Policy' => 'no-referrer',
        ]);

        return $response;
    }
}

CORS 与 API 暴露

  • config/cors.php 中限制来源
  • 对于经过身份验证的路由,避免使用通配符来源
// config/cors.php
return [
    'paths' => ['api/*', 'sanctum/csrf-cookie'],
    'allowed_methods' => ['GET', 'POST', 'PUT', 'PATCH', 'DELETE'],
    'allowed_origins' => ['https://app.example.com'],
    'allowed_headers' => [
        'Content-Type',
        'Authorization',
        'X-Requested-With',
        'X-XSRF-TOKEN',
        'X-CSRF-TOKEN',
    ],
    'supports_credentials' => true,
];

日志记录与 PII

  • 切勿记录密码、令牌或完整的卡片数据
  • 在结构化日志中编辑敏感字段
use Illuminate\Support\Facades\Log;

Log::info('User updated profile', [
    'user_id' => $user->id,
    'email' => '[REDACTED]',
    'token' => '[REDACTED]',
]);

依赖项安全

  • 定期运行 composer audit
  • 谨慎固定依赖项版本,并在出现 CVE 时及时更新

签名 URL

使用签名路由生成临时的、防篡改的链接。

use Illuminate\Support\Facades\URL;

$url = URL::temporarySignedRoute(
    'downloads.invoice',
    now()->addMinutes(15),
    ['invoice' => $invoice->id]
);
use Illuminate\Support\Facades\Route;

Route::get('/invoices/{invoice}/download', [InvoiceController::class, 'download'])
    ->name('downloads.invoice')
    ->middleware('signed');
Source repo
affaan-m/ECC
Skill path
docs/zh-CN/skills/laravel-security/SKILL.md
Commit SHA
4e973d3eaf92
Repository license
MIT
Data collected