Development › Authentication
Authentication
Authentication establishes who the caller is. Authorization (separate doc) decides what they may do.
#Baseline
This starter uses Laravel Sanctum for API token / SPA cookie authentication (laravel/sanctum).
Typical pieces:
app/Models/User— authenticatable modelapp/Security/Authentication— app-specific auth services/guards helpersapp/Modules/Auth— auth-facing application/presentation boundariesconfig/sanctum.php+ personal access tokens migration
#API authentication pattern
- Issue a token (or session cookie for first-party SPA) via the Auth module.
- Protect routes with
auth:sanctum(or the project’s configured guard). - Resolve the user in Controllers / Policies via
$request->user()— never trust client-supplied user IDs without auth.
Route::middleware(class="tk-s">'auth:sanctum')->group(function () {
class="tk-c">// module routes
});Module providers may apply middleware when loading routes, or you can group inside Presentation/Routes/api.php.
#Rules
- Controllers stay thin — login/register flows call Auth Application Actions.
- Passwords are hashed with Laravel’s hasher; never log secrets or tokens.
- Prefer short-lived tokens / rotation policies in production.
- CORS and cookie domains must be configured explicitly for SPA auth.
#Local development
php artisan migrate
# register / login via Auth module endpoints once wiredUse Feature tests with Sanctum::actingAs($user) (or $this->actingAs) rather than real tokens when testing protected APIs.