Agent skill

Laravel Sessions Middleware

by HoangNguyen0403 in HoangNguyen0403/agent-skills-standard

Configure Redis session drivers, register security-header middleware, and prevent session fixation in Laravel.

MITAuto-check: notesBackend & APIs

Install Laravel Sessions Middleware

skills CLI
$ npx skills add HoangNguyen0403/agent-skills-standard --skill laravel-sessions-middleware -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HoangNguyen0403/agent-skills-standard laravel-sessions-middleware --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HoangNguyen0403/agent-skills-standard.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/laravel/laravel-sessions-middleware .claude/skills/laravel-sessions-middleware && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
laravel-sessions-middleware
GitHub stars
572
Token cost
~830 tokens
SKILL.md length
283 words
Files
3 (incl. references)
Skills in repo
211
Repo updated
First seen
Licence
MIT

At a glance

Configure Redis session drivers, register security-header middleware, and prevent session fixation in Laravel.

  • Works in 4 steps: Set Redis driver — SESSION_DRIVER=redis… → Regenerate on login — Call… → Create security middleware — Add HSTS,… → …
  • Switching session drivers
  • SKILL.md covers Priority: P1 (HIGH), Workflow: Secure Sessions &…, Security Headers Middleware… and Implementation Guidelines, plus 4 more sections
  • Calls php

What it does

Laravel Sessions Middleware is an agent skill from HoangNguyen0403/agent-skills-standard. Configure Redis session drivers, register security-header middleware, and prevent session fixation in Laravel. Use when switching session drivers, adding HSTS/CSP headers via middleware, or regenerating sessions after login.

Its SKILL.md is about 830 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `evals/evals.json` and `references/implementation.md`).

It sits in Backend & APIs, covering Backend development and Secure coding. It works with Laravel, Redis and PHP. The repository describes itself as: A collection of Agent Skills Standard and Best Practice for Programming Languages, Frameworks that help our AI Agent follow best practies on frameworks and programming laguages. The licence is MIT.

When your agent uses it

  • Switching session drivers
  • Adding HSTS/CSP headers via middleware
  • Regenerating sessions after login

Example prompts

  • “/laravel-sessions-middleware”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Set Redis driver — SESSION_DRIVER=redis in .env; install predis/predis.
  2. Regenerate on login — Call $request->session()->regenerate() after authentication.
  3. Create security middleware — Add HSTS, CSP, X-Frame-Options, and X-Content-Type-Options headers.
  4. Register globally — Use withMiddleware(fn($m) => $m->append(...)) in bootstrap/app.php.

What it can do on your machine

Read from SKILL.md and the folder at commit b529c2d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • php

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Laravel Sessions Middleware loads about 830 tokens when it runs, and up to ~1.2k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 283 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~830
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:22
    is driver** — `SESSION_DRIVER=redis` in `.env`; install `predis/predis`.
  • NoteMentions a .env fileSKILL.md:35
    rs**: Set **`SESSION_DRIVER=redis`** in `.env` for production/scaled environments.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HoangNguyen0403/agent-skills-standard at commit b529c2d, republished under its MIT licence (© HoangNguyen0403). 283 words, ~830 tokens.

Download SKILL.mdSave it as .claude/skills/laravel-sessions-middleware/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
laravel-sessions-middleware
description
Configure Redis session drivers, register security-header middleware, and prevent session fixation in Laravel. Use when switching session drivers, adding HSTS/CSP headers via middleware, or regenerating sessions after login.

Laravel Sessions & Middleware

Priority: P1 (HIGH)

Workflow: Secure Sessions & Add Middleware

  1. Set Redis driver — SESSION_DRIVER=redis in .env; install predis/predis.
  2. Regenerate on login — Call $request->session()->regenerate() after authentication.
  3. Create security middleware — Add HSTS, CSP, X-Frame-Options, and X-Content-Type-Options headers.
  4. Register globally — Use withMiddleware(fn($m) => $m->append(...)) in bootstrap/app.php.

Security Headers Middleware Example

See implementation examples for security headers middleware and directory structure.

Implementation Guidelines

Session Architecture
  • Drivers: Set SESSION_DRIVER=redis in .env for production/scaled environments.
  • Dependencies: Install predis/predis and avoid file driver due to I/O lock issues at scale.
  • Security: Call $request->session()->regenerate() after successful authentication to prevent session fixation. Call $request->session()->invalidate() on logout.
  • Access: Never access env('SESSION_DRIVER') directly in code; always use config('session.driver'). Clear caches via php artisan config:clear.
Middleware Pipeline
  • Custom Middleware: Use php artisan make:middleware EnsureTokenIsValid. Implement handle(Request $request, Closure $next): Response.
  • Registration: Register new middleware in bootstrap/app.php using withMiddleware().
  • Security Headers: Standardize HSTS, CSP, X-Frame-Options, and X-Content-Type-Options in dedicated security middleware. Register as global middleware.
  • Priority: Use withMiddleware(fn($m) => $m->append(MyMiddleware::class)) or prepend() for highest priority.
  • Performance: Avoid heavy computation in global middleware; delegate these to domain services.

Anti-Patterns

  • No file session driver in production: Use Redis or Memcached instead.
  • No env() for session config: Use config('session.*') instead.
  • No heavy logic in Middleware: Delegate complex logic to Services.
  • No sensitive data in cookies: Store securely in server sessions only.

References

Middleware performance checklist

  • File sessions create I/O and locking problems at scale; prefer a production session backend and keep global middleware cheap and deterministic.

Canonical response anchors

When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:

  • avoids file-session I/O,locking problems,scaled production
  • cheap and deterministic,Keep the middleware lightweight
  • CSP
  • prepend()
  • session fixation
  • withMiddleware()

© HoangNguyen0403, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/laravel/laravel-sessions-middleware of HoangNguyen0403/agent-skills-standard.

  • SKILL.md
  • evals/evals.json
  • references/implementation.md

Open the folder on GitHubat commit b529c2d

Compare with similar skills

Laravel Sessions Middleware next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Laravel Sessions Middleware compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Laravel Sessions Middleware this skillHoangNguyen0403/agent-skills-standard572—~830Automated safety check: NotesMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Laravel Best Practicesanonaddy/anonaddy4.9k13 repos~1.2kAutomated safety check: PassMIT
Geoflowyaojingang/GEOFlow3.8k—~722Automated safety check: PassAGPL-3.0
Livewire Developmentcoollabsio/coolify63k—~964Automated safety check: PassMIT

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Laravel Best Practices

    anonaddy/anonaddy

    Apply this skill whenever writing, reviewing, or refactoring Laravel PHP code.

    4.9k GitHub starsUsed in 13 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Geoflow

    yaojingang/GEOFlow

    Operate/develop GEOFlow CLI/Laravel/admin/API, topics/专题 and topic tasks, theme libraries/replication, sites/leads/Agent, channel sync and legacy yao-geoflow-cli/design/template migration.

    3.8k GitHub stars~722 tokensUpdated today
    Backend & APIsAuto-check passed
  • Livewire Development

    coollabsio/coolify

    A skill your agent uses for any task or question involving Livewire.

    63k GitHub stars~964 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Laravel Specialist

    Jeffallan/claude-skills

    Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed

More from HoangNguyen0403/agent-skills-standard

All 211 skills in this repo
  • Subagent-Driven Development

    HoangNguyen0403/agent-skills-standard

    Runs a multi-task implementation plan by sending each task to a fresh implementer subagent, reviewing it independently, then reviewing the whole branch.

    572 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • draw.io Architecture Diagramming

    HoangNguyen0403/agent-skills-standard

    Draws architecture diagrams as editable draw.io files from a JSON spec, with a fixed house style, one C4 level per diagram and evidence-tagged shapes.

    572 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Android Navigation 3 Guide

    HoangNguyen0403/agent-skills-standard

    Implements and migrates to Jetpack Navigation 3 in Compose: NavDisplay, typed route objects, a state-list back stack, deep links, multiple back stacks and dialog scenes.

    572 GitHub stars~687 tokensUpdated yesterday
    Auto-check passed
  • Angular HttpClient Standards

    HoangNguyen0403/agent-skills-standard

    Sets rules for Angular HTTP code: functional interceptors, typed requests, services that own every call, and httpResource for reactive data loading in Angular 17+.

    572 GitHub stars~652 tokensUpdated yesterday
    Auto-check passed
  • Angular Tooling

    HoangNguyen0403/agent-skills-standard

    Angular CLI usage, code generation, build configuration, and bundle optimization.

    572 GitHub stars~743 tokensUpdated yesterday
    Auto-check passed
  • Common Code Review

    HoangNguyen0403/agent-skills-standard

    Conduct high-quality, persona-driven code reviews. An agent skill from HoangNguyen0403/agent-skills-standard.

    572 GitHub stars~772 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Laravel Sessions Middleware

What does Laravel Sessions Middleware do?

Configure Redis session drivers, register security-header middleware, and prevent session fixation in Laravel. Laravel Sessions Middleware is an agent skill from HoangNguyen0403/agent-skills-standard. Configure Redis session drivers, register security-header middleware, and prevent session fixation in Laravel.

When should I use Laravel Sessions Middleware?

Laravel Sessions Middleware fits situations like: switching session drivers; adding HSTS/CSP headers via middleware; regenerating sessions after login.

How do I install Laravel Sessions Middleware in Claude Code?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill laravel-sessions-middleware -a claude-code`. Or copy the skill folder (skills/laravel/laravel-sessions-middleware in HoangNguyen0403/agent-skills-standard) into .claude/skills/laravel-sessions-middleware in your project. Claude Code loads it when a task matches its description.

How do I install Laravel Sessions Middleware in Codex?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill laravel-sessions-middleware -a codex`. Or copy the skill folder (skills/laravel/laravel-sessions-middleware in HoangNguyen0403/agent-skills-standard) into .agents/skills/laravel-sessions-middleware in your project. Codex loads it when a task matches its description.

Can I use Laravel Sessions Middleware in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HoangNguyen0403/agent-skills-standard --skill laravel-sessions-middleware -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/laravel-sessions-middleware, .gemini/skills/laravel-sessions-middleware, .github/skills/laravel-sessions-middleware and .opencode/skills/laravel-sessions-middleware in your project.

What does Laravel Sessions Middleware need to run?

Going by SKILL.md and its folder, Laravel Sessions Middleware needs the command-line tools its instructions call (php).

Does Laravel Sessions Middleware access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Laravel Sessions Middleware safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Laravel Sessions Middleware use?

Laravel Sessions Middleware is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Laravel Sessions Middleware use?

About 830 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 350 tokens, read only when the agent opens those files.

What are the alternatives to Laravel Sessions Middleware?

Skills that share tags, products or a category with Laravel Sessions Middleware: Configuring Horizon (coollabsio/coolify, 63k stars), Fortify Development (coollabsio/coolify, 63k stars), Laravel Best Practices (anonaddy/anonaddy, 4.9k stars) and Geoflow (yaojingang/GEOFlow, 3.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Laravel Sessions Middleware?

HoangNguyen0403 (a GitHub user) maintains it in HoangNguyen0403/agent-skills-standard, which has 572 GitHub stars. The repository holds 211 skills in this directory. The repository was last updated on October 9, 2026.

Source: HoangNguyen0403/agent-skills-standard on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.