Auth is the one thing you don't wing
·2 min read ·Security · Backend · Laravel
I've worked on codebases where authentication was 'we'll figure it out later.' Later always arrives at the worst possible time—during a security audit, after a breach, or when you need to add a mobile app and your session-based auth doesn't translate.
Get auth right from the beginning. It's the one thing you can't bolt on cleanly afterward.
The Common Mistakes
Storing tokens in localStorage. Any JavaScript running on your page can read localStorage, making it vulnerable to XSS. Use httpOnly cookies for session tokens—they're inaccessible to JavaScript by design.
No refresh token strategy. Short-lived access tokens are good. But without a refresh mechanism, users get logged out every hour. Tokens that never expire are just long-lived passwords.
Rolling your own password hashing. Use bcrypt. Laravel uses it by default via Hash::make(). Don't touch this.
No rate limiting on auth endpoints. A login endpoint without rate limiting is an open invitation for brute force attacks.
Laravel Makes This Reasonably Easy
For APIs consumed by mobile apps or SPAs, Sanctum gives you token-based auth with sensible defaults:
// User gets a token on login
$token = $user->createToken('mobile-app')->plainTextToken;
// Revoke all tokens on password change
$user->tokens()->delete();
The Questions You Have to Answer Explicitly
- What happens when a user changes their password? Invalidate all tokens.
- When a user logs out from one device, do other sessions stay valid?
- What's the lifetime of a 'remember me' session?
These are product decisions, not just technical ones. Make them deliberately, not by accident.
Auth is boring to get right. It's catastrophic to get wrong.