/laravel-sessions-middleware
Configure Redis session drivers, register security-header middleware, and prevent session fixation in Laravel. Use when switching session drivers, adding HSTS/CSP headers via middleware, or regenerating sessions after login.
$ npx -y skills add hoangnguyen0403/agent-skills-standard --skill laravel-sessions-middleware --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/laravel-sessions-middleware
Context preview
The summary Claude sees to decide when to auto-load this skill.
Configure Redis session drivers, register security-header middleware, and prevent session fixation in Laravel. Use when switching session drivers, adding HSTS/CSP headers via middleware, or regenerating sessions after login.
SKILL.md
laravel-sessions-middleware.SKILL.mdname: laravel-sessions-middleware
description: Configure Redis session drivers, register security-header middleware, and prevent session fixation in Laravel. Use when switching session drivers, adding HSTS/CSP headers via middleware, or regenerating sessions after login.
metadata:
triggers:
files:
- 'app/Http/Middleware/**/*.php'
- 'config/session.php'
keywords:
- session
- driver
- handle
- headers
- csrfLaravel Sessions & Middleware
**Priority: P1 (HIGH)**
Workflow: Secure Sessions & Add Middleware
1. **Set Redis driver** — `SESSION_DRIVER=redis` in `.env`; install `predis/predis`. 2. **Regenerate on login** — Call `$request->session()->regenerate()` after authentication. 3. **Create security middleware** — Add HSTS, **CSP**, X-Frame-Options, and X-Content-Type-Options headers. 4. **Register globally** — Use `withMiddleware(fn($m) => $m->append(...))` in `bootstrap/app.php`.
Security Headers Middleware Example
See [implementation examples](references/implementation.md#security-headers-middleware) for security headers middleware and directory structure.
Implementation Guidelines
Session Architecture
- **Drivers**: Set **`SESSION_DRIVER=redis`** in `.env` for production/scaled environments.
- **Dependencies**: Install **`predis/predis`** and **avoid file driver** due to I/O lock issues at scale.
- **Security**: Call **`$request->session()->regenerate()`** after successful authentication to prevent **session fixation**. Call **`$request->session()->invalidate()`** on logout.
- **Access**: **Never access `env('SESSION_DRIVER')`** directly in code; always use **`config('session.driver')`**. Clear caches via **`php artisan config:clear`**.
Middleware Pipeline
- **Custom Middleware**: Use **`php artisan make:middleware EnsureTokenIsValid`**. Implement **`handle(Request $request, Closure $next): Response`**.
- **Registration**: Register new middleware in **`bootstrap/app.php`** using **`withMiddleware()`**.
- **Security Headers**: Standardize **HSTS, CSP, X-Frame-Options, and X-Content-Type-Options** in dedicated security middleware. Register as **global** middleware.
- **Priority**: Use **`withMiddleware(fn($m) => $m->append(MyMiddleware::class))`** or **`prepend()`** for highest priority.
- **Performance**: **Avoid heavy computation** in global middleware; delegate these to domain services.
Anti-Patterns
- **No file session driver in production**: Use Redis or Memcached instead.
- **No `env()` for session config**: Use `config('session.*')` instead.
- **No heavy logic in Middleware**: Delegate complex logic to Services.
- **No sensitive data in cookies**: Store securely in server sessions only.
References
- [Advanced Middleware Patterns](references/implementation.md)
Middleware performance checklist
- File sessions create I/O and locking problems at scale; prefer a production session backend and keep global middleware cheap and deterministic.
Canonical response anchors
When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:
- avoids file-session I/O,locking problems,scaled production
- cheap and deterministic,Keep the middleware lightweight
- CSP
- prepend()
- session fixation
- withMiddleware()
Read more
name: laravel-sessions-middleware
description: Configure Redis session drivers, register security-header middleware, and prevent session fixation in Laravel. Use when switching session drivers, adding HSTS/CSP headers via middleware, or regenerating sessions after login.
metadata:
triggers:
files:
- 'app/Http/Middleware/**/*.php'
- 'config/session.php'
keywords:
- session
- driver
- handle
- headers
- csrfLaravel Sessions & Middleware
**Priority: P1 (HIGH)**
Workflow: Secure Sessions & Add Middleware
1. **Set Redis driver** — `SESSION_DRIVER=redis` in `.env`; install `predis/predis`. 2. **Regenerate on login** — Call `$request->session()->regenerate()` after authentication. 3. **Create security middleware** — Add HSTS, **CSP**, X-Frame-Options, and X-Content-Type-Options headers. 4. **Register globally** — Use `withMiddleware(fn($m) => $m->append(...))` in `bootstrap/app.php`.
Security Headers Middleware Example
See [implementation examples](references/implementation.md#security-headers-middleware) for security headers middleware and directory structure.
Implementation Guidelines
Session Architecture
- **Drivers**: Set **`SESSION_DRIVER=redis`** in `.env` for production/scaled environments.
- **Dependencies**: Install **`predis/predis`** and **avoid file driver** due to I/O lock issues at scale.
- **Security**: Call **`$request->session()->regenerate()`** after successful authentication to prevent **session fixation**. Call **`$request->session()->invalidate()`** on logout.
- **Access**: **Never access `env('SESSION_DRIVER')`** directly in code; always use **`config('session.driver')`**. Clear caches via **`php artisan config:clear`**.
Middleware Pipeline
- **Custom Middleware**: Use **`php artisan make:middleware EnsureTokenIsValid`**. Implement **`handle(Request $request, Closure $next): Response`**.
- **Registration**: Register new middleware in **`bootstrap/app.php`** using **`withMiddleware()`**.
- **Security Headers**: Standardize **HSTS, CSP, X-Frame-Options, and X-Content-Type-Options** in dedicated security middleware. Register as **global** middleware.
- **Priority**: Use **`withMiddleware(fn($m) => $m->append(MyMiddleware::class))`** or **`prepend()`** for highest priority.
- **Performance**: **Avoid heavy computation** in global middleware; delegate these to domain services.
Anti-Patterns
- **No file session driver in production**: Use Redis or Memcached instead.
- **No `env()` for session config**: Use `config('session.*')` instead.
- **No heavy logic in Middleware**: Delegate complex logic to Services.
- **No sensitive data in cookies**: Store securely in server sessions only.
References
- [Advanced Middleware Patterns](references/implementation.md)
Middleware performance checklist
- File sessions create I/O and locking problems at scale; prefer a production session backend and keep global middleware cheap and deterministic.
Canonical response anchors
When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:
- avoids file-session I/O,locking problems,scaled production
- cheap and deterministic,Keep the middleware lightweight
- CSP
- prepend()
- session fixation
- withMiddleware()
The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.
Repo: hoangnguyen0403/agent-skills-standard
Other skills on agent-skills-standard.
- /android-agp-upgrade
Upgrade an Android project to Android Gradle Plugin (AGP) 9. Use when migrating to AGP 9, updating Gradle build files, migrating to built-in Kotlin, or adopting the new AGP DSL.
Open skill - /android-architecture
Apply Clean Architecture layering, modularization, and Unidirectional Data Flow in Android projects. Use when setting up project structure, placing code in layers, configuring feature/core modules, or implementing UDF patterns; defer Compose state and ViewModel/StateFlow
Open skill - /android-background-work
Implement WorkManager and background processing correctly on Android. Use when creating Worker classes, scheduling tasks, choosing between WorkManager and Foreground Services, or setting up Hilt in workers; defer FCM and notification delivery to android-notifications.
Open skill - /android-compose-migration
Migrate an Android XML View to Jetpack Compose following a structured 10-step workflow. Use when converting XML layouts to Compose, setting up Compose in an existing View-based project, or incrementally adopting Compose.
Open skill - /android-compose
Build high-performance declarative UI with Jetpack Compose. Use when writing Composable functions, optimizing recomposition, hoisting state, or working with LazyColumn and side effects; defer deep-link and navigation routing to android-navigation.
Open skill - /android-concurrency
Write correct coroutine scopes, lifecycle collection, and dispatcher injection in Android production code. Use for suspend functions, coroutine scopes, and dispatcher mechanics; defer ViewModel StateFlow/LiveData architecture, Fragment lifecycle recipes,
Open skill

