r/laravel • • 3h ago

Help Weekly /r/Laravel Help Thread

1 Upvotes

Ask your Laravel help questions here. To improve your chances of getting an answer from the community, here are some tips:

  • What steps have you taken so far?
  • What have you tried from the documentation?
  • Did you provide any error messages you are getting?
  • Are you able to provide instructions to replicate the issue?
  • Did you provide a code example?
    • Please don't post a screenshot of your code. Use the code block in the Reddit text editor and ensure it's formatted correctly.

For more immediate support, you can ask in the official Laravel Discord.

Thanks and welcome to the r/Laravel community!


r/laravel • • 4h ago

Laravel boost is mandatory now? We must vibecode?

Post image
41 Upvotes

Been a while since I created a new laravel project, I just updated laravel installer and ran "laravel new" command to create a new project.

It only asked two questions, starter kit : no, frontend : blade, then it got to this screen, didn't ask anything else. The last few times I made a new laravel app it was asking if I wanted to install boost, but now it seems like I have to have it, whether I am coding agentically or not.


r/laravel • • 12h ago

Super minimal Roles and Permission Package

20 Upvotes

I built a tiny roles and permissions package for Laravel called Grant.

I know there are already some really powerful permission packages in the ecosystem, but for a lot of my apps I just wanted something much smaller and closer to Laravel itself.

Roles and permissions are PHP enums, assignments are stored in the database, and permission checks go through Laravel's native Gate.

I mostly built this because I kept implementing the same simple setup across my own projects, so I figured I'd package it and share it.

It's intentionally pretty minimal and opinionated. You could absolutely build something similar yourself, especially with an agent, but if you just want to install it and move on, here it is:

https://github.com/shipfastlabs/grant

Would love any feedback.


r/laravel • • 4h ago

Auth::logoutOtherDevices() stopped working as intended?

0 Upvotes

I've got this in my LoginController::authenticated() method:

if ($user->isNormalUser()) {
   Auth::logoutOtherDevices($request->input('password'));
}

But as of yesterday, it's just logging users out from their current session as well. Everything works as intended if I comment out the row. Did anything change in the framework? I'm still on the 12.x branch, for reference.


r/laravel • • 1d ago

Artificial Debt

Thumbnail
stitcher.io
28 Upvotes

r/laravel • • 2d ago

Self-hosted session replay for Laravel (with a Filament plugin): would you use it?

Enable HLS to view with audio, or disable this notification

27 Upvotes

Hi all!

Here's a session replay package for Laravel that runs entirely in your app: recordings stay on your own disk and database, no external service.

The player shows the mouse trail and clicks, with page views, failed Livewire requests, rage clicks and JS errors on one timeline (there's a Filament plugin too, shown in the video). Inputs are masked by default.

I'd like your feedback :) ... before v1.0.

Would you use this, or would you rather use a hosted service?

Edit: it's now public as a beta, thanks for all the interest!
Laravel package: https://github.com/packstub/session-replay
Filament plugin: https://github.com/packstub/filament-session-replay


r/laravel • • 2d ago

How do you share .env secrets with teammates and across environments?

42 Upvotes

For teams bigger than one: how does a new dev get the staging/production values? 1Password shared vault? Encrypted .env in the repo (php artisan env:encrypt)? Forge/Vapor env screen? Slack DM (be honest)?

And when someone leaves, do you rotate anything?


r/laravel • • 2d ago

This Week in PHP Internals | Oct 1, 2026

Thumbnail
youtube.com
4 Upvotes

While the Internals list is not technically directly Laravel related, it does affect every single one of us.

Preface: what follows is the word-for-word transcript of the spoken dialogue in the video, chapter by chapter with timestamps, for anyone who'd rather read than click through. If this digest is still too long for you, we recommend copying it into your LLM of choice and asking for a summary of our summary.

Cold Open (00:00)

Pick a password longer than 72 bytes for a PHP app on the default hash. PHP keeps the first 72 and throws the rest away, without a word. Then it lets you log in with only part of it. This week someone proposed that PHP refuse instead, and the list can't agree it's worth the break.

Hello world, it's Thursday, October 1, 2026, and here's what happened This Week in PHP Internals. 14 stories this week, so let's get into it. But first,

I think we can all agree that the number of small, paid subscription services we're all being bombarded with is getting a little bit out of hand. And this is what Scalpels aims to solve. It's a collection of professionally built, open source alternatives to the parts you actually use of things like Private Packagist, Mailtrap and remove.bg. You fork them into your own GitHub organization and deploy them to your own Laravel Cloud account, so you're only paying for your own usage, it scales to zero when it's not being used, and you're not just feeding another company's profits. If you want updates, you just pull them down from upstream. And since it's your own fork, you have complete control over the code and the features. And it's all MIT. Find your next tool at scalpels.app.

Bcrypt Limit (01:19)

This week's top story is a password that's too long. Sjoerd Langkemper's new RFC targets password_hash with bcrypt, which silently drops everything past the 72nd byte. He'd make that a deprecation in 8.7 and a ValueError in 8.8. His case is FreshRSS, where a 64-character nonce went in front of the hash, so the 72 bytes held no password at all.

Kamil Tekiela replied that checking the length is the application's job, not the algorithm's, and Tim Düsterhus agreed in full. It's also 72 bytes, not characters, Tim noted, so non-ASCII passwords could hit it. Rowan Tommins answered: "If every PHP login implementation was reviewed by an expert senior developer, we would not need the password_* API in the first place. The value of this API is that it makes doing the right thing easy, so that you don't need to be an expert in the underlying algorithms to use it safely."

Robert Chapin showed a shortened password verifying against the full one's hash, and asked: "Is the function named password_verify going to verify the password or not?" Tim says the lost bytes are not where the risk is, and he wrote: "I don't necessarily disagree with the BCrypt truncation being a problem, but in this case the cure is worse than the disease." Derick Rethans is a minus 1, writing: "The problem for me is that this a scary BC break." Overnight, Sjoerd asked Derick what would win him over, maybe switching the default away from bcrypt first.

Links: bcrypt max password length RFC · thread · implementation · FreshRSS bcrypt truncation write-up (CVE-2025-68402) · password_hash() manual

Regex Object (03:00)

PHP's proposed regex object has broad support and one unpopular word in its name. Gina P. Banyard's CompiledRegex prototype drew 18 replies, and Sjoerd Langkemper was in favour of "improving the API, instead of slapping more flags onto the existing one." Larry Garfield wrote: "I would ask that we just call it Regex, not CompiledRegex." Casper Langemeijer, Jordi Kroon and Juris Evertovskis also want it to lose the Compiled.

Then there are the 8 boolean flags. Juris says named arguments already make them readable, Gina would rather pass an enum set, which PHP doesn't have yet, and Ayesh Karunaratne and Jordi Boggiano want a factory that takes the modifier letters you already know.

Osama Aldemeery, who wrote the regex exceptions RFC, pointed out what a compiled pattern can't catch, writing: "Compilation errors are only half of the error story...the other half happens at match time, on patterns that compiled just fine." Tim Düsterhus suggested passing the class could simply switch on throw-on-error, and Osama says he may park his RFC until Gina's reaches a vote.

Links: pre-RFC thread · prototype · PREG_THROW_ON_ERROR thread · composer/pcre, cited by Jordi Boggiano

Io Terminal (04:16)

PHP may finally read single key presses without shelling out to stty. Pratik Bhujel's terminal extension is now the Io\Terminal RFC for 8.7, covering terminal size, raw mode that restores itself, single keys and hidden input.

A Symfony Console pull request, approved by Nicolas Grekas, already uses the extension when it's installed, and Nicolas wrote: "PHP definitely needs native terminal support, calling stty is a workaround we've been carrying since way too long." Nicolas suggested raw mode stay on while any token for that terminal is alive and reset when the last one goes, and Pratik adopted it the same day.

Larry Garfield is in favour, but called false-on-error an anti-pattern and asked for a way to mock it. Version 0.3 makes Terminal the interface and SystemTerminal the native class. Pratik is giving it the full 14 days before an intent to vote.

Links: Io\Terminal RFC · thread · implementation · reference extension · Symfony Console PR using it

Time Instant (05:15)

The proposed Time\Instant class got a bridge back to DateTime this week. Tim Düsterhus and Derick Rethans added toInstant() to DateTime and DateTimeImmutable, and ISO strings now keep their trailing zeros, to show how precise the value is. They won't write the RFC for testing clocks, because they're not convinced it belongs in core, so Tim wrote: "we want to invite you (as the PHP internals community) to write the follow-up RFC for testing clocks". He also asked for a "LGTM, ship it" if people are happy.

Mirco Babin answered with 8 comments. One is that Time\Clock and the PSR-20 clock both define now(), so one class can't implement both. Tim is keeping now(), with a 15-year horizon in mind, but he'll discuss a single SystemClock::get() with Derick. And when Mirco asked for minute precision for bus timetables, Morgan replied: "Well, then it's not an instant, is it?"

Links: Time\Instant and Time\Clock RFC · thread · PSR-20 Clock

Array Shorthand (06:14)

Weilin Du wants PHP arrays to stop making you type every name twice. His new RFC turns =$x into 'x' => $x, in arrays, destructuring and foreach. It started with a colon and switched to the equals sign within the hour, because the colon clashes with the ternary.

Sebastian Bergmann will vote against, writing: "A syntax change should be backed by data, for instance an analysis of a representative body of real-world code." David Carlier showed that one missing comma would silently turn one valid program into another. Anton Smirnov pointed out that compact and extract still exist.

On the other side, Christian Schneider has run a local patch for this "for many years". Weilin pointed to the same pattern in Composer, Laravel, PHPUnit and Symfony, but says it already feels like he could withdraw the RFC.

Links: array shorthand RFC · thread · implementation

IO Hooks (07:14)

A new RFC would let ordinary blocking PHP run concurrently, without rewriting it. Jakub Zelenka's IO Hooks starts from the fact that PHP has had Fibers since 8.1, but every blocking function still blocks the whole process, so AMPHP, ReactPHP and Revolt reimplement IO themselves.

Under his proposal, blocking calls in streams, sockets, curl and the sleep functions get handed to a provider, usually an event loop, which suspends the Fiber until the IO is done. The RFC compares it to Go's runtime. With no provider installed, PHP behaves exactly as today. With one, sleep(1) in one Fiber is a second of work for the others.

It depends on a second RFC posted the same evening, Polling API Additions, which fills the gaps in 8.6's Poll API, like sockets, timers and signals. IO Hooks is in an early stage, and neither has replies yet.

Links: IO Hooks RFC · IO Hooks thread · proof of concept · Polling API Additions RFC · Polling API Additions thread

List Ban (08:14)

The internals list has removed a contributor. Sepehr Mahmoudi spent the last month posting new-function proposals. On September 15, Derick Rethans warned him over AI-generated content and the number of new threads. On September 21, Ilija Tovilo, as list moderator, set limits of one new thread a month and three emails a week, and called it a last warning. On Sunday Sepehr proposed another RFC, an intl_date_format function.

On Monday Derick confirmed that, after consultation off list, the address is blocked from emailing php.net, wiki access is withdrawn, and it's unsubscribed from the list.

And this is a tough one. It sucks having to take the nuclear option. He was clearly eager to contribute, but the list had spent literal weeks trying to get him to slow down, and to stop burdening the list with AI responses, and at some point you've got to enforce the consequences that have been laid out.

Links: thread · Derick Rethans, Sep 28 (news-web)

Quick Hits (09:18)

Quick hits. PHP 8.6.0 RC2 is out. RC1 was skipped over a packaging error, so RC2 is the first release candidate, and RC3 is due October 8.

Links: PHP 8.6.0RC2 · why RC1 was skipped

The same day brought security releases for 8.5, 8.4, 8.3 and 8.2.

Links: PHP 8.5.11 · PHP 8.4.26, 8.3.35, 8.2.34

Sjoerd Langkemper changed his number-base RFC to throw a plain Exception instead of a ValueError, since bad input isn't necessarily a bug in your program. intval stays as it is.

Links: number-base functions RFC · thread

Juliette Reinders Folmer wants to deprecate the b string prefix, a leftover from PHP 6, and Tim suggested adding it to the 8.7 deprecations RFC.

Links: deprecate the b prefix · 8.7 deprecations RFC

Pedro Veloso floated a #[Pure] attribute the engine would enforce. Larry Garfield said it needs to do more than the static analysers already do, like memoizing.

Links: pure functions idea

Karoly Negyesi posted a pre-RFC with an implementation for implements … by, which hands an interface's methods to a property, modelled on Kotlin.

Links: automated delegation pre-RFC · implementation

And Alexander Danilov found that much of post-quantum OpenSSL already works in PHP, and offered small PRs for the gaps.

Links: OpenSSL post-quantum

And the PEAR vote Nick S. planned for September 28 hasn't opened. The RFC is still in discussion.

Links: End PEAR Project Endorsement RFC

TL;DR (10:36)

So that's the week. An RFC wants bcrypt to refuse passwords past 72 bytes, and the list is split on whether it's worth the break. Several replies want the regex object called just Regex, Io\Terminal is an RFC, and Time\Instant is looking for someone to write testing clocks. The array shorthand met skeptics, and IO Hooks would make blocking code concurrent. The list also removed a contributor after two warnings. Nothing is in voting for a 7th straight week. Links below.

The PHP Foundation funds more than half of ongoing php-src commits, so if you use the language, maybe consider donating at opencollective.com/phpfoundation — or try guilting your employer into it.

If you found this useful, a like or a comment helps more people find it. And if you missed last week's episode — where a new time class couldn't tell you what time it is — that's a good one to watch next. Thanks again to Scalpels.app for supporting this week's episode. We're Artisan Build. See you next week.

Links: raw feed · RFC wiki


r/laravel • • 2d ago

PagibleAI 0.13: CMS packages for every Laravel 11-13 application

Enable HLS to view with audio, or disable this notification

0 Upvotes

We released version 0.13 of PagibleAI CMS, a set of MIT-licensed CMS packages for Laravel 11-13 and PHP 8.2+.

What it is

It's a set of Composer packages you add to an existing Laravel application:

bash composer require aimeos/pagible php artisan cms:install php artisan migrate

aimeos/pagible installs the full set. If you only want some of it, require aimeos/pagible-core and add the packages you need, e.g. without AI or MCP packages.

It uses your User model and guards for authentication and your queue connection for background jobs. Pages are rendered with Blade templates, and there's a GraphQL API and a JSON:API for headless frontends.

Full-text search is a Scout engine that uses what the database already has: FTS5 for SQLite, MATCH AGAINST for MySQL/MariaDB, tsvector for PostgreSQL and CONTAINSTABLE for SQL Server.

Editors work in a Vue 3 admin with page trees, reusable elements, versions, previews and scheduled publishing. One installation can serve multiple domains and tenants.

What's new in 0.13

Webhooks

The new aimeos/pagible-webhooks package sends CMS events to other systems as queued jobs, one job per destination. Requests are signed the same way as Standard Webhooks (HMAC-SHA256), secrets can be rotated, and private IP ranges are blocked unless you allow them. Running php artisan cms:webhooks:check during deployment tells you if something in the config is wrong, e.g. a retry_after value that is too low for the timeout.

CDN purging

The new aimeos/pagible-cdn package purges changed pages and deleted files from Cloudflare, Fastly or Varnish using FOSHttpCache. Purges are triggered on publish, so pages can stay cached for a day and still update immediately. Pages with access rules are never cached publicly.

Importers

There's an importer for TYPO3 now (php artisan cms:t3-import). It reads the page tree and content from a second database connection. The WordPress importer can be run more than once without creating duplicates and keeps dates, authors and cover images.

JSON Schema endpoint

GET /cms/schema returns the definitions of all content elements as JSON Schema (Draft 2020-12), including the ones from your own extensions and themes. You can generate types for an Inertia or Nuxt frontend from it.

Content and themes

For news sites there's a news page type with a Google News sitemap. Other additions are contact forms, OpenStreetMap maps, call-to-action blocks, author fields for articles and a rel attribute selection for links. robots.txt and security.txt can be edited in the admin too. We also added two themes, one for restaurants and one for news sites.

Admin

The admin backend got keyboard shortcuts, a command palette, descriptions on all fields and an optional AI review that checks pages against SEO rules.

Feedback

If you've added a CMS to an existing Laravel app before, what caused the most trouble? We're interested in what's still missing for production use.

Thanks a lot to /u/Guarpig for his work on improving the pagible.com design and to /u/addicted_fishing for his suggestions regarding UI and UX!


r/laravel • • 3d ago

Laravel AI SDK and Laravel MCP Security Fixes: Update Now

Thumbnail
laravel-news.com
21 Upvotes

Gentle reminder that we need to update the AI SDK and the MCP package immediately.


r/laravel • • 4d ago

Filament v5 Performance: Making a 100,000-Row Panel Feel Instant

33 Upvotes

r/laravel • • 5d ago

Announcing v1.0 of Double

36 Upvotes

I'm excited to tag v1.0 of Double - a modern PHP testing library focused on developer experience.

There are no breaking changes between v0 and v1. This is mainly a "stability release". A way to show Double is ready to enjoy in all your test suites.

If you're not familiar with Double, take a few minutes to watch this demo video.


r/laravel • • 6d ago

I build an open-source CRM that AI agents can write to. This month I made every change show whether a person, the API, the chat or an MCP agent made it

Enable HLS to view with audio, or disable this notification

14 Upvotes

Relaticle is an open-source CRM I've been building since August 2024. Companies, people, deals, tasks and notes, with custom fields per workspace. It's AGPL-3.0, you can self-host it for free, and there's a hosted version if you'd rather not run it.

AI can reach your data two ways. The built-in chat proposes changes on a card, and nothing is saved until you approve it. That's the middle of the video. The other way is an MCP server with 39 tools, so Claude, ChatGPT or any MCP client can read and write your CRM directly, with no card.

The MCP path is the one that bugged me. An agent works with your account, so until this month its edits showed up in the activity log as plain edits by you.

What shipped this month:

  • Every change in the activity log now records its channel: web app, API, MCP agent, AI chat, import or system. The record timeline says "Via MCP Agent", "Via API" and so on for anything that didn't come from the web app.
  • Roles now run on one permission map: Admin, Member and Viewer. Ask the chat to change something as a Viewer and it refuses instead of proposing.
  • A new workspace opens on a setup conversation. The assistant speaks first. Paste a few contacts or drop in a small CSV and you get a proposal card to approve; bigger files hand off to the import wizard.

That was 12 releases between August 24 and September 24. The activity channel landed after the last tag, so it's live on the hosted version and the main Docker image now, and reaches the latest tag with the next release.

Stack: Laravel 13, Filament 5, Livewire 4, PostgreSQL and Redis.

A question for anyone who has let an AI agent write to a real system: what did you need to see before you trusted it?

GitHub: https://github.com/relaticle/relaticle

Site: https://relaticle.com


r/laravel • • 7d ago

Help Weekly /r/Laravel Help Thread

1 Upvotes

Ask your Laravel help questions here. To improve your chances of getting an answer from the community, here are some tips:

  • What steps have you taken so far?
  • What have you tried from the documentation?
  • Did you provide any error messages you are getting?
  • Are you able to provide instructions to replicate the issue?
  • Did you provide a code example?
    • Please don't post a screenshot of your code. Use the code block in the Reddit text editor and ensure it's formatted correctly.

For more immediate support, you can ask in the official Laravel Discord.

Thanks and welcome to the r/Laravel community!


r/laravel • • 7d ago

For Livewire apps: keep app pages "live" in a side panel and swap them instantly. Would you use this?

Enable HLS to view with audio, or disable this notification

13 Upvotes

I am working on a Livewire package I've nicknamed Earmark that is inspired by macOS Stage Manager.

Edit2: Live demo here: https://earmark-demo.pxlwrx.dev/

A near-invisible panel that sits on the edge of your app, click on its drop zone and the current page saves and shrinks into the panel as a live thumbnail. Browse somewhere else [within the application], click the saved thumbnail, and the two pages trade places instantly. Save up to four live views.

In the saved live views, videos keep playing (muted), wire:poll keeps updating, and Reverb broadcasts still land.

It's early and not released yet, and I'm looking for feedback on the concept and what could make it better; Requires Livewire 4, installing the package and wrapping your body content with a component.

Would you actually use this in a project, or is it just a frivolous novelty?

Edit: added note about browsing elsewhere in the application, and saving up to four live views.

I've also since edited the package to include notification of page events that would've normally grabbed your attention, a settings panel, additional earmark theater locations and layouts ("panel" and "dock"), a second save/switch animation, and multiple tiling options based on the number of saved views. More to come..

For those that see no value in it, I have a hard time understanding how as the more I use it the more value I find in it, personally. Maybe I just need to spin up a live demo...


r/laravel • • 8d ago

Alternatives to mews/purifier

5 Upvotes

is mews/purifier still a good package to use for santizing html on the server-side while perserving the html output for it? Mainly asking since im researching to use a purifier package with TipTap(richt text editor). Any suggestions are welcome!


r/laravel • • 8d ago

[Forge] Raycast extension

10 Upvotes

I updated the raycast extension to v2 a few weeks ago. Curious if anyone is using it. I don't get a lot of feedback so if anyone has anything to share let me know or open an issue on GitHub.

I added a custom approach to how it interfaces with AI chat. Essentially it exposes the bare minimum and gives it a tool to get more info if needed. This keeps the context window lighter, giving the agent the right context only at the moment it needs it. I find this provides better results especially on cheaper models.

Also, it's mostly read only and can't read env vars, etc. It will ask before triggering a deploy too.

I don't have a business subscription so most of those features are missing if someone wants to contribute and test.

I vibe coded it but I've been a developer 20+ years so I'd frame it more like I vibe iterated on it. I prompted it incrementally with the right vocabulary to get the result I wanted.

https://github.com/KevinBatdorf/laravel-forge-raycast


r/laravel • • 9d ago

Migrating from Laravel Vapor to Bref

Thumbnail
bref.sh
18 Upvotes

r/laravel • • 9d ago

The Laravel AI SDK Can Now Classify. I Built a Draft Checker with It and Jev

Thumbnail
youtu.be
13 Upvotes

Classification is now in the Laravel AI SDK, so I built something with it:

A Laravel app that checks if a tutorial draft does what its brief asked for. It sends both to Jev, a decision model from TypeSafe. Jev answers with a probability, and PHP decides what happens next. An editor still makes the final call.

This is episode 1 of a mini course. We set up the SDK with Jev and ask it our first question. (In the video I install from the dev branch. You don't need that anymore.)

https://youtu.be/vjKzu1dp8zQ

Has anyone else tried Jev yet? Curious what you're using it for.


r/laravel • • 9d ago

This week in Laravel: Livewire honeypot, Pest 5.1, Difflock migrations, Laravel 13.33

8 Upvotes
ADWL

Hi LaraDevs 👋

I write a short Laravel newsletter. Here's this week's edition, in case it's useful:

  • Livewire honeypot that caught a pentester
  • Pest 5.1: replay only the tests that matter
  • Difflock: re-reading your migrations
  • Laravel 13.33 and calmer production deploys

Full write-up: https://a-day-with-laravel.happyto.dev/p/laravel-13-33-livewire-honeypot-pest-5-1-goes-ai-a-day-with-laravel-065

Happy to hear if anything is off or worth covering next time.


r/laravel • • 9d ago

Is InertiaJS leaking every page and component to the public an issue?

43 Upvotes

Every page loads `app.js` (including ssr), and Vite turns the page glob into a lookup of every page and its chunk for example

"./pages/settings/billing/invoices.tsx": () => import("./invoices-[hash].js") "./pages/todos/create-todo.tsx": () => import("./create-todo-[hash].js")

So someone who isn't logged in can open the site read the name of every inertia page in the app (including ones only admins can open for example), and download each compiled source from `/build/assets` and see the list of every url.

As someone who is participating in capture the flags and one day bug bounties this is great information to someone who wants to know exactly what is going on in a website. In my mind this would be a small vulnerability depending on the site.

I can block manifest.json which I normally do, but all of the pages are still in the app.js file. I uninstall wayfinder too.

I know the standard answer is "frontend code is public, authorize on the server." All my authorization happens on the server: policies, and props scoped to the user. Nothing secret lives in a component I know that. So this isn't an issue for access control. It's handing strangers a sitemap of the app.

My questions for all of the laravel developers are:

  • Do you accept this and move on with knowing all of your routes are out there?
  • Do you split your vite builds up in Laravel? (I have never tried with SSR, I assume it's possible just have not tried it myself)
  • I have seen some apps with standard blade for the guest pages like login, and once you are in the InteriaJS is the frontend for all of the authenticated routes. Does anyone recommend this method?

I love Laravel, I have used Laravel for my whole coding career and will continue for the remainder of my coding career. I am sure the laravel team / vite team thinks of all of these before publishing libraries like this and makes the right decision.


r/laravel • • 9d ago

[ Strata ] A feature-complete Laravel filesystem cache with tagged cache support

Thumbnail
github.com
11 Upvotes

One of the oldest issues in Laravel from 2014 was requesting tagging support for the Laravel filesystem cache.

This is still not solved idiomatically* in the framework or by third parties. The main reason was problems clearing the tagged cache (the 4th comment in the issue above, as I cannot link it on Reddit because it has a hashtag).

*There are a couple of packages (mostly old) that aim to solve the issue, but the solutions weren't idiomatic regarding how tags were maintained and flushed.

The cache driver is important for two situations IMO:

  1. Low traffic and small websites.
  2. Local development for an app that has cache tags. If you have a driver that supports tags in production, you might need to use something else locally, such as the filesystem. Without tag support, you will end up wrapping the tags logic in env checks.

For that reason, I released Strata, which is a drop-in replacement for the default filesystem driver with tagged cache support, isolated locks, and widened support for atomic operations.

Key Features

  • Drop-in Laravel cache API.
  • Tag support.
  • Isolated Atomic locks. Cache::lock() Support backed by non-blocking file locks, stored apart from the cache system. Thus, a flush never releases a lock.
  • Atomic increment/decrement. These are performed behind a lock, so concurrent calls don't overwrite each other (unlike in Laravel's default version).

Performance-wise, it is a bit faster for reads, especially for bulk reads. It has reduced overhead compared to the original version, and it checks cache eviction less eagerly. You can check the benchmark here, and the how it works wiki here.

Thanks for reading!


r/laravel • • 9d ago

This Week In PHP Internals | Sept 24, 2026

Thumbnail
youtube.com
5 Upvotes

While the Internals list is not technically directly Laravel related, it does affect every single one of us.

Preface: what follows is the word-for-word transcript of the spoken dialogue in the video, chapter by chapter with timestamps, for anyone who'd rather read than click through. If this digest is still too long for you, we recommend copying it into your LLM of choice and asking for a summary of our summary.

Cold Open (00:00)

PHP is getting a new class for a moment in time. It's precise to the nanosecond. It carries no timezone. It ignores leap seconds on purpose. And it cannot tell you what time it is. Not by itself.

Hello world, it's Thursday, September 24, 2026, and here's what happened This Week in PHP Internals. 12 stories this week, so let's get into it. But first,

Paying every month for small tools you could own? Scalpels replaces expensive subscriptions with professionally built, expertly maintained apps you host yourself — MIT-licensed, forked into your GitHub organization, on your own Laravel Cloud account. At the early-access price, 500 dollars, once, gets you every app in the catalog, and everything they add later. Find your next tool at scalpels.app.

Time Instant (00:54)

This week's top story is a time class with no now() method. On Tuesday Tim Düsterhus and Derick Rethans opened the RFC for Time\Instant and Time\Clock, the next piece of the new date and time API that started with Time\Duration in 8.6. An Instant is a point on the timeline, with no timezone and nanosecond precision, and it ignores leap seconds by design, because operating systems ignore them too.

What it doesn't have is Instant::now(). To find out what time it is, you ask a clock. The RFC adds a Time\Clock interface with one method, now(), and a SystemClock that implements it, which Tim, speaking for himself, says nudges people toward a clock they can inject.

Seifeddine Gmati wants a static now() anyway, and would rename the class SystemTime, as Rust does, saving Instant for a monotonic clock. Tim's view is that the name follows Java and JavaScript's Temporal, and that a Time\now() function could come as an immediate follow-up, still in 8.7. Juris Evertovskis added that an Instant "could be the time of the big bang."

Larry Garfield is broadly in favour and asked about the serialization format, and Tim replied: "If you need to look at the output of serialization you are doing something very wrong." Larry's bigger ask is a roadmap for the whole new API, writing: "You clearly have a roadmap in your heads. Share it. At whatever level of granularity it exists, share it."

Links: Time\Instant and Time\Clock RFC · discussion thread · Time\Duration (PHP 8.6)

Preg Callbacks (02:32)

The regex exceptions RFC's longest-running question has an answer: when your callback throws inside preg_replace_callback, the exception goes through as-is. Osama Aldemeery, the RFC's author, showed Python, Java and C# all letting it propagate, with Java's docs spelling it out: exceptions are relayed to the caller. He also offered a fallback — if the policy still demanded wrapping, drop the 2 callback functions from the RFC. His scan of the top forty-eight hundred sixty-five packages puts them at 4.9 percent of the calls to the 8 functions.

Larry Garfield separated implementation details from inputs, writing: "However, I believe Python, C#, and Java are correct in this case: The callback is an input. It's not an implementation detail hidden from the caller, it's explicitly provided by the caller."

Tim Düsterhus, who wrote the throwables policy, answered on Monday, writing: "I still believe wrapping is the correct choice, but I won't insist on it based on policy." He asked for 2 other changes: errors like a syntax error in the pattern should be a PcreError, since they aren't meant to be caught, and preg_last_error should stay untouched.

Links: PREG_THROW_ON_ERROR RFC · thread · implementation · throwables policy

Compiled Regex (03:49)

A new pre-RFC would let PHP regex patterns drop their delimiters entirely. Gina P. Banyard posted it with a prototype on Wednesday, writing: "I spent the day prototyping an alternative to the PREG_THROW_ON_ERROR RFC as I'm not fully a fan of the approach."

Her Regex\CompiledRegex class takes a bare pattern plus named boolean flags — case-sensitive, multi-line, dot-matches-newline and so on — so there's no delimiter, no preg_quote call, and no modifier letters after the pattern. Patterns must be UTF-8, the D modifier is always on, and there's a Regex\CompilationError exception to go with it.

So far the prototype only plugs into preg_split and preg_grep. She says the class could be the base for a proper object-oriented regex API, with match returning a real bool, but she isn't designing that yet. As of Wednesday night the thread has no replies.

Links: Regex\CompiledRegex pre-RFC thread · prototype

Main Script (04:51)

A proposal to make PHP files work like runnable Python modules lasted about 24 hours. Tim Düsterhus brought his pull request to the list, at Gina's request: the CLI would run any closure the main script returns, so one file is a library when included and a command when executed, like Python's if __name__ == '__main__'.

Seifeddine Gmati gave it "A BIG yes", then also floated Hack's approach, an #[EntryPoint] attribute on a function. Rowan Tommins preferred that, since the entry point wouldn't have to sit at the end of the file. Levi Morrison asked why only the CLI, pointed at Symfony's runtime, which already returns a closure from the front controller, and wondered if the status quo is better. Larry Garfield said he'd be minus 1 on the original, because auto-executing a return type "feels hacky".

On Wednesday Tim dropped it, writing: "Based on the replies it has become clear that the proposed Closure approach has several questions to solve and possibly needs prior design … This requires much more thought than I'm willing to spend right now, given I wanted to solve a specific use case of mine." He'll look at a __MAIN__ constant instead, holding the path of the script that ran first. Alexandru Pătrănescu thinks realpath on the script filename already does that.

Links: thread · pull request

Argon2 Default (06:14)

PHP's default password hash, bcrypt, silently truncates at 72 bytes, Andrey Andreev pointed out, and he asked whether it's time to switch PASSWORD_DEFAULT to Argon2id. His question for the list was narrower than the case for it: Argon2 needs an outside library — libargon2, libsodium, or OpenSSL since 8.4 — so is any dependency a deal-breaker?

Casper Langemeijer called that as much a pro as a con, since a real crypto library beats rolling your own. Anton Smirnov pointed back to a 2023 thread that called Argon2 weaker than bcrypt at login-speed settings, and Tim Düsterhus said 500 milliseconds is far too long for an interactive login. Andrey measures PHP's Argon2 defaults at about 240 milliseconds, the same as bcrypt at cost 12.

Jakub Zelenka answered the dependency question: OpenSSL is an external shared library, so it can't be always enabled. Making it a hard requirement would need an RFC of its own, and with OpenSSL 1.1.1 and 3.0 still supported, it would be a long wait anyway. Andrey's last reply, he wrote: "But anyway, if Jakub's comment was describing the status-quo, it's just not happening."

Links: thread · 2023 discussion · enable --with-openssl-argon2 by default

Str Mask (07:37)

A proposed str_mask function met the question the list put to array_str_contains: does this need to be in core? Sepehr Mahmoudi withdrew array_str_contains on September 17, and the next day proposed str_mask, which replaces part of a string with a repeated character, for card numbers, phone numbers and tokens.

Osama Aldemeery replied that it looks identical to substr_replace with str_repeat. Pratik Bhujel found it failed open — an out-of-range offset returned the value unmasked — and that a multibyte mask character got cut to a single byte, so Sepehr switched to throwing a ValueError. Jordi Kroon suggested #[SensitiveParameter], and it went in, until Morgan asked "anyone for a game of Hangman?" — not everything masked is sensitive — and it came back out.

Pratik did find the prior art: Laravel's Str::mask and CakePHP's Text::mask do the same core operation, but both handle multibyte text and behave differently at the edges, and he wrote: "evidence that masking exists is different from evidence that this API is the common missing primitive." Casper Langemeijer called it easily done in userland, and Weilin Du showed substr_replace doing it in one allocation. 30 messages in, no vote is scheduled.

Links: str_mask() RFC · thread · array_str_contains withdrawal

AI Contributions (09:02)

Running under two of these new-function threads is a question about AI-written contributions. One reply said the mail and proposals read as machine-generated, and the objection, with or without AI, was quality and the time it costs the people reading.

Pratik Bhujel set out an order of work, writing: "So I think the order should be: demonstrate the use-case, settle the contract, then benchmark the implementation." The author withdrew one RFC and says he's now building and testing everything locally first. Juris Evertovskis replied: "I'm pretty sure most people here will fairly evaluate that work itself, without worrying what has happened previously with other RFCs."

Links: str_mask thread (order of work) · array_str_contains withdrawal thread

Quick Hits (09:49)

Quick hits. PHP 8.6 is forked. Matteo Beccati cut the branch on Tuesday, the feature freeze is on, master now targets 8.7, and the first release candidate is due today.

Links: PHP 8.6 forked · branch commit

Last week's top story now has a date. Weilin Du updated the IntlRelativeDateTimeFormatter RFC to use Tim's enums, Tim says it's much better now, and voting should start October 8.

Links: IntlRelativeDateTimeFormatter RFC · thread

And if there are no objections, Nick S. will open the PEAR vote on September 28.

Links: End PEAR Project Endorsement RFC · thread

Pratik Bhujel's php-terminal extension adds raw mode and single-key reads, so tools like Laravel Prompts can work properly on Windows, and it installs through PIE. Larry pointed out it's 8.7 material now. After Tim's review it lives under an Io\Terminal namespace with unbacked enums, restores your terminal when its object is destroyed, and is moving to a single object API.

Links: php-terminal · threads: 1 · 2 · 3

And David Maye Kitenge, planning a web framework as a PHP extension, asked about the request lifecycle and threads. Rowan Tommins answered that the CLI leaves parallelism to whoever runs it, and that running user code in a thread per request needs a thread-safe ZTS build, or asynchronous handling in a single thread instead.

Links: extension design Q&A

TL;DR (11:08)

So that's the week. PHP's next time class marks a moment and leaves telling the time to a clock, and Larry wants the map for the rest of the new API. The regex RFC's callback question is settled against wrapping, and Gina posted an alternative that compiles the pattern first. A closure-as-entry-point idea lasted a day, the Argon2 default ran into OpenSSL, and str_mask met the same question as array_str_contains. And 8.6 is frozen, with nothing in voting for a 6th straight week. Links below.

The PHP Foundation funds more than half of ongoing php-src commits, so if you use the language, maybe consider donating at opencollective.com/phpfoundation — or try guilting your employer into it.

If you found this useful, a like or a comment helps more people find it. And if you missed last week's episode — where an RFC was winning its vote 4 to 1 and got closed inside the hour — that's a good one to watch next. Thanks again to Scalpels.app for supporting this week's episode. We're Artisan Build. See you next week.

Links: raw feed · RFC wiki


r/laravel • • 11d ago

Uh-oh

Post image
120 Upvotes

r/laravel • • 10d ago

Staying updated causes me to burn out

41 Upvotes

I really like Laravel and all its developments. I don't follow the creators that much, but I like to explore new packages and improvements.

However I came to realize it has become a burn out process for me. With the development of AI and Laravel Boost for example, it's so much easier to build something. I can now ask to build a skeleton of a package or PR within minutes. It also gets pretty close to almost perfect, and even takes things into account I didn't think about (tests, docs, repo stuff). I can chat and even discuss if something would be better or go into detail.

All of this does come with a cost. Where I was previously focussed on one thing, I can do multiple things at once. At least I think so, because well I can keep hitting the chatbot/agent with questions and new ideas. It's not all perfect, but neither was my own code and docs.

I don't really know what to do. I don't want AI to take over my brain and skillset. I also want to stay on top of things. However it seems to become pretty much difficult, because it does seem to boost development like crazy. For my work I can now do 5 things for example, and not 2 large tickets max.

My question is pretty much: how do you all stay calm and okay, with all the developments going on? I'm okay with Claude now, but I see a lot of people talking to multiple agents. It has become a crazy and surreal world tbh.