Urgent.News

What's breaking now, across thousands of outlets.

Tech

Laravel Routing Basics: web.php, api.php & Resource Routes

Laravel routing looks simple until the day you ask "why does this route return a CSRF error" or "why did my API route just lose the user's session." Both questions trace back to the same thing: web.php and api.php aren't just two files that happen to hold different URLs — they run through different middleware stacks with different assumptions baked in. This is Part 1 of a series on Laravel…

Laravel routing can seem straightforward until you encounter issues like CSRF errors or session loss in API routes. The files web.php and api.php are not merely placeholders for different URLs; they process requests through distinct middleware stacks with predefined assumptions. This article is the first in a series that delves into Laravel routing in production environments, covering how routes are matched and handled, the differences between Laravel 11's route structure, the distinction between web.php and api.php, and the resource route shortcut that defines seven routes simultaneously.

A closure route, which maps an HTTP verb and URI to a request handler function, is suitable for quick redirects or static pages. However, it lacks a name, cannot be cached like controller routes, and can accumulate unwanted logic. Instead, it is advisable to route to a controller method for more complex requests.

In Laravel 11 and later, route files are no longer located in app/Providers/RouteServiceProvider.php. Instead, they are established directly in bootstrap/app.php using Application::configure(). The api.php file no longer exists in a fresh Laravel 11 installation, but you can create it using the php artisan install:api command, which scaffolds the file, integrates it with Laravel Sanctum for token authentication, and places it in the web middleware stack.

The primary difference between web.php and api.php lies in their middleware groups. web.php routes utilize the web middleware group, which handles session management, CSRF token verification, and cookie encryption, crucial for maintaining user sessions across requests. Conversely, api.php routes run through the api middleware group, devoid of session or CSRF middleware, aligning with Laravel's design philosophy of stateless APIs that do not rely on cookies for user identification.

This distinction is often overlooked, leading to errors when attempting to use session() or CSRF protection within api.php routes, resulting in "session store not set on request" issues.

To mitigate such issues, it is essential to understand that the session middleware must be included in the request stack for proper session handling. If an API must support stateful sessions, Laravel Sanctum's EnsureFrontendRequestsAreStateful middleware can be incorporated selectively to cater to authenticated frontend requests while maintaining stateless behavior for others.

The Route::resource shortcut simplifies the creation of CRUD routes for controllers, automatically generating seven routes (index, create, store, show, edit, update, destroy) based on a single line of code. This feature streamlines the development process, particularly for API controllers that primarily involve JSON interactions. For APIs that do not necessitate HTML form generation, apiResource can be employed to automatically create the five JSON-relevant routes.

A unique aspect of Route::resource is its handling of the parameter {post}, which represents a model rather than an ID, allowing for more flexible route definitions and interactions with resources within the application.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Apple Shouldn't Dictate Your App's Redesign Schedule

Apple's design team doesn't know what's on your backlog. A new iOS appearance might be exactly what you want for your next release.

  • Apple's design team doesn't dictate app redesign schedule.
  • iOS 27 theme with Liquid Glass effects can be selected during build.
  • Developers decide when to adopt new iOS appearance.

More from Saturday 3 October →