Field Manual PHP / Laravel reference
← Security

Sessions

Sessions associate a browser with authenticated server-side state.

What it is

Sessions associate a browser with authenticated server-side state.

When to use it

Regenerate at login and invalidate at logout.

Syntax

$request->session()->regenerate();

Example

Auth::logout();
$request->session()->invalidate();
$request->session()->regenerateToken();
// On HTTPS deployments: SESSION_SECURE_COOKIE=true
// Keep HttpOnly enabled and choose SameSite appropriately.

Common mistakes

Do not store credentials in localStorage; local HTTP secure cookies will not be sent.

Related topics

Browse Security