Form requests saved my codebase
·2 min read ·Laravel · Backend · Best Practices
Before I started using Laravel Form Requests consistently, my controllers had blocks of $request->validate([...]) scattered everywhere. Same rules duplicated across create and update endpoints. Authorization checks mixed in with validation. Tests that had to fake entire HTTP requests to verify a validation rule.
Form Requests fixed all of that.
What a Form Request Actually Is
A Form Request is a dedicated class that handles two things: authorization and validation. Nothing else.
php artisan make:request StorePostRequest
class StorePostRequest extends FormRequest
{
public function authorize(): bool
{
return $this->user()->can('create', Post::class);
}
public function rules(): array
{
return [
'title' => ['required', 'string', 'max:255'],
'content' => ['required', 'string', 'min:100'],
'tags' => ['array', 'max:5'],
'tags.*' => ['string', 'exists:tags,name'],
];
}
public function messages(): array
{
return [
'content.min' => 'Posts must be at least 100 characters.',
];
}
}
Your controller receives already-validated, authorized data:
public function store(StorePostRequest $request): JsonResponse
{
$post = $this->postService->create($request->validated());
return response()->json($post, 201);
}
The Testing Win
You can now test your validation rules directly on the Form Request class without booting the HTTP layer. Fast, focused, explicit tests.
The Authorization Win
Putting authorization in authorize() means it runs before your controller code even starts. If the user isn't allowed, they get a 403. Your controller never sees the request. Clean separation.
Form Requests are one of those Laravel features that feel like a small quality-of-life improvement until you've used them everywhere and gone back to a codebase that doesn't use them.