auth middleware, meaning users must be logged in before they can view or manage tasks.
Route protection
The task and profile routes are wrapped in anauth middleware group in routes/web.php:
verified middleware:
Unauthenticated requests to any of the above routes are automatically redirected to
/login by Laravel’s authentication middleware.Session-based auth flow
Authentication is entirely session-based. On a successful login, Laravel creates a server-side session and issues a session cookie to the browser. Every subsequent request carries that cookie, and Laravel resolves the authenticated user from the session store without requiring tokens or additional headers.Login workflow
1
Visit the login page
The root URL
/ renders the Auth:Login Inertia view. The guest middleware group in routes/auth.php also exposes the login form directly at /login:2
Submit credentials
The form POSTs to
/login, handled by AuthenticatedSessionController@store. Laravel validates the credentials against the users table (email + hashed password).3
Session is created
On success, a new session is started, the user is marked as authenticated, and the browser receives a session cookie. The user is redirected to their intended destination (or
/tasks/index by default — the task.index named route as configured in AuthenticatedSessionController).4
Access protected routes
With a valid session cookie, the user can access all routes inside the
auth middleware group — including /tasks and all task API endpoints.Registration workflow
New accounts are created through/register, which is also behind the guest middleware so already-authenticated users cannot access it:
Password reset
Full password reset is available via the following routes, all behind theguest middleware:
Email verification
For authenticated users who have not yet verified their email, the following routes are available:Password confirmation
Sensitive operations can require the user to re-enter their current password before proceeding:Profile management
Authenticated users can manage their account through three profile endpoints:Logout
Logging out destroys the current session and invalidates the session cookie:Logout uses a
POST request (not GET) to protect against cross-site request forgery. Breeze includes the required CSRF token automatically in all forms.